Vulnerability Description
Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Publiccms | Publiccms | < 4.0.202011.b |
Related Weaknesses (CWE)
References
- https://github.com/sanluan/PublicCMS/commit/0f4c4872914b6a71305e121a7d9a19c07cdePatchThird Party Advisory
- https://github.com/sanluan/PublicCMS/issues/51ExploitIssue TrackingThird Party Advisory
- https://github.com/sanluan/PublicCMS/commit/0f4c4872914b6a71305e121a7d9a19c07cdePatchThird Party Advisory
- https://github.com/sanluan/PublicCMS/issues/51ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2021-27693?
CVE-2021-27693 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.
How severe is CVE-2021-27693?
CVE-2021-27693 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-27693?
Check the references section above for vendor advisories and patch information. Affected products include: Publiccms Publiccms.