Vulnerability Description
A code injection vulnerability has been discovered in the Upgrade function of QibosoftX1 v1.0. An attacker is able execute arbitrary PHP code via exploitation of client_upgrade_edition.php and Upgrade.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qibosoft | Qibosoft | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/whiskey-jj/w2s2x2222.github.io/issues/2ExploitIssue TrackingThird Party Advisory
- https://www.cnvd.org.cn/flaw/show/2297879Third Party Advisory
- https://github.com/whiskey-jj/w2s2x2222.github.io/issues/2ExploitIssue TrackingThird Party Advisory
- https://www.cnvd.org.cn/flaw/show/2297879Third Party Advisory
FAQ
What is CVE-2021-27811?
CVE-2021-27811 is a vulnerability with a CVSS score of 7.2 (HIGH). A code injection vulnerability has been discovered in the Upgrade function of QibosoftX1 v1.0. An attacker is able execute arbitrary PHP code via exploitation of client_upgrade_edition.php and Upgrade...
How severe is CVE-2021-27811?
CVE-2021-27811 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27811?
Check the references section above for vendor advisories and patch information. Affected products include: Qibosoft Qibosoft.