CVE-2021-20104

HIGH

Machform < 16 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded with forms through upload.php.

References (1)

Core 1

Scores

CVSS v3 8.1
EPSS 0.0129
EPSS Percentile 79.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
machform/machform < 16
Published Jun 29, 2021
Tracked Since Feb 18, 2026