Vulnerability Description
cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read through this vulnerability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cmseasy | Cmseasy | 7.7.5_20211012 |
Related Weaknesses (CWE)
References
- https://jdr2021.github.io/2021/10/14/CmsEasy_7.7.5_20211012%E5%AD%98%E5%9C%A8%E4ExploitThird Party Advisory
- https://jdr2021.github.io/2021/10/14/CmsEasy_7.7.5_20211012%E5%AD%98%E5%9C%A8%E4ExploitThird Party Advisory
FAQ
What is CVE-2021-42644?
CVE-2021-42644 is a vulnerability with a CVSS score of 6.5 (MEDIUM). cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_dat...
How severe is CVE-2021-42644?
CVE-2021-42644 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-42644?
Check the references section above for vendor advisories and patch information. Affected products include: Cmseasy Cmseasy.