CVE-2021-34816

HIGH

Etherpad 1.8.13 - Command Injection

Title source: llm
STIX 2.1

Description

An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by installing plugins from an attacker-controlled source.

Scores

CVSS v3 7.2
EPSS 0.0044
EPSS Percentile 63.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-88
Status published
Products (1)
etherpad/etherpad 1.8.13
Published Jul 21, 2021
Tracked Since Feb 18, 2026