CVE-2021-20104

HIGH

Machform < 16 - Unauthenticated Remote Code Execution via File Attachment Upload

Title source: llm
STIX 2.1

Description

Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded with forms through upload.php.

References (1)

Core 1

Scores

CVSS v3 8.1
EPSS 0.0215
EPSS Percentile 79.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
machform/machform < 16
Published Jun 29, 2021
Tracked Since Feb 18, 2026