Vulnerability Description
ChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to upload and execute an arbitrary file via a POST request to resources.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Churchdesk | Churchrota | 2.6.4 |
Related Weaknesses (CWE)
References
- https://github.com/Little-Ben/ChurchRotaThird Party Advisory
- https://github.com/rmccarth/cve-2021-3164ExploitThird Party Advisory
- https://github.com/Little-Ben/ChurchRotaThird Party Advisory
- https://github.com/rmccarth/cve-2021-3164ExploitThird Party Advisory
FAQ
What is CVE-2021-3164?
CVE-2021-3164 is a vulnerability with a CVSS score of 8.8 (HIGH). ChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to upload and execute an arbitrary file via a POST request to reso...
How severe is CVE-2021-3164?
CVE-2021-3164 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3164?
Check the references section above for vendor advisories and patch information. Affected products include: Churchdesk Churchrota.