packetstormsecurity.com
http://packetstormsecurity.com/files/164445/Maian-Cart-3.8-Remote-Code-Execution.html CVE-2021-32172
CRITICALNuclei
maianscriptworld maian_cart Missing Authorization
Record summary
CVE-2021-32172 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
maian_cartBrowse maianscriptworld / maian_cart | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBMaian-Cart 3.8 - Remote Code Execution (RCE) (Unauthenticated)ExploitDB exploitby DreyAndNot analyzed1 file
Nuclei templates
1ProjectDiscoveryCRITICALMaian Cart <=3.8 - Remote Code ExecutionCVSS 9.8
Maian Cart 3.0 to 3.8 via the elFinder file manager plugin contains a remote code execution vulnerability.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
Remediation
Upgrade to a patched version of Maian Cart (>=3.8) to mitigate this vulnerability.
WeaknessesCWE-862
Authorspdteam
Template tagscve2021cverceunauthmaianintrusivemaianscriptworldvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:maianscriptworld:maian_cart:3.8:*:*:*:*:*:*:*
https://dreyand.github.io/maian-cart-rce/ https://github.com/DreyAnd/maian-cart-rce https://www.maianscriptworld.co.uk/critical-updates https://nvd.nist.gov/vuln/detail/CVE-2021-32172 https://www.maianscriptworld.co.uk/
Source: ProjectDiscovery
References
5dreyand.github.io
https://dreyand.github.io/maian-cart-rce github.com
https://github.com/DreyAnd/maian-cart-rce nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-32172 maianscriptworld.co.uk
https://www.maianscriptworld.co.uk/