Vulnerability Description
Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user has to alternate the files of a vaild file backup. This leads of leaking the database credentials in the environment variables.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redaxo | Redaxo | 5.12.1 |
Related Weaknesses (CWE)
References
- https://github.com/evildrummer/CVE-2021-XYZ2ExploitThird Party Advisory
- https://github.com/evildrummer/MyOwnCVEs/tree/main/CVE-2021-39458ExploitThird Party Advisory
- https://github.com/evildrummer/CVE-2021-XYZ2ExploitThird Party Advisory
- https://github.com/evildrummer/MyOwnCVEs/tree/main/CVE-2021-39458ExploitThird Party Advisory
FAQ
What is CVE-2021-39458?
CVE-2021-39458 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user has to alternate the files of a vaild file backup. This leads of leaking the...
How severe is CVE-2021-39458?
CVE-2021-39458 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-39458?
Check the references section above for vendor advisories and patch information. Affected products include: Redaxo Redaxo.