CVE-2021-29995

HIGH

CloverDX < 5.7.1 - Cross-Site Request Forgery in Server Console

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-29995. PoCs published by niebardzo.

AI-analyzed exploit summary This exploit demonstrates a CSRF to RCE vulnerability in CloverDX by cracking the ViewState and chaining requests to execute a reverse shell payload. It requires an authenticated victim and a Java-based ViewState cracker.

Description

A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution). The issue is resolved in CloverDX 5.10, CloverDX 5.9.1, CloverDX 5.8.2, and CloverDX 5.7.1.

Exploits (1)

exploitdb WORKING POC
by niebardzo · pythonwebappsjava
https://www.exploit-db.com/exploits/50166

This exploit demonstrates a CSRF to RCE vulnerability in CloverDX by cracking the ViewState and chaining requests to execute a reverse shell payload. It requires an authenticated victim and a Java-based ViewState cracker.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: CloverDX versions 5.9.0, 5.8.1, 5.8.0, 5.7.0, 5.6.x, 5.5.x, 5.4.x
Auth required
Prerequisites: Authenticated victim session · Java-based ViewState cracker · Inbound connection to CloverDX
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://support.cloverdx.com/releases/

Scores

CVSS v3 8.8
EPSS 0.0421
EPSS Percentile 89.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
cloverdx/cloverdx < 5.7.1
Published Jun 09, 2021
Tracked Since Feb 18, 2026