CVE-2021-32172
CRITICAL EXPLOITED NUCLEIMaianscriptworld Maian Cart - Missing Authorization
Title source: ruleDescription
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.
Exploits (1)
Nuclei Templates (1)
Maian Cart <=3.8 - Remote Code Execution
CRITICALby pdteam
References (4)
Scores
CVSS v3
9.8
EPSS
0.6546
EPSS Percentile
98.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2024-09-19
CWE
CWE-862
Status
published
Products (1)
maianscriptworld/maian_cart
3.8
Published
Oct 07, 2021
Tracked Since
Feb 18, 2026