CVE-2021-23258

MEDIUM

Crafter CMS Spring SPEL - Authenticated OS Command Execution

Title source: manual
STIX 2.1

Description

Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SPEL Expression does not have security restrictions, which will cause attackers to execute arbitrary commands remotely (RCE).

References (1)

Core 1
Core References

Scores

CVSS v3 4.2
EPSS 0.0070
EPSS Percentile 48.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-913
Status published
Products (1)
craftercms/crafter_cms 3.1.0 - 3.1.12
Published Dec 02, 2021
Tracked Since Feb 18, 2026