Vulnerability Description
Pear Admin Think through 2.1.2 has an arbitrary file upload vulnerability that allows attackers to execute arbitrary code remotely. A .php file can be uploaded via admin.php/index/upload because app/common/service/UploadService.php mishandles fileExt.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pearadmin | Pearadmin Think | <= 2.1.2 |
Related Weaknesses (CWE)
References
- https://gitee.com/pear-admin/Pear-Admin-Think/issues/I3DI3TExploitIssue TrackingThird Party Advisory
- https://gitee.com/pear-admin/Pear-Admin-Think/issues/I3DI3TExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2021-29377?
CVE-2021-29377 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Pear Admin Think through 2.1.2 has an arbitrary file upload vulnerability that allows attackers to execute arbitrary code remotely. A .php file can be uploaded via admin.php/index/upload because app/c...
How severe is CVE-2021-29377?
CVE-2021-29377 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-29377?
Check the references section above for vendor advisories and patch information. Affected products include: Pearadmin Pearadmin Think.