CVE-2021-34816

HIGH

Etherpad 1.8.13 - Command Injection

Title source: llm
STIX 2.1

Description

An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by installing plugins from an attacker-controlled source.

References (2)

Core 2
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/ether/etherpad-lite/releases
Exploit, Third Party Advisory x_refsource_misc
https://blog.sonarsource.com/etherpad-code-execution-vulnerabilities

Scores

CVSS v3 7.2
EPSS 0.0223
EPSS Percentile 80.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-88
Status published
Products (1)
etherpad/etherpad 1.8.13
Published Jul 21, 2021
Tracked Since Feb 18, 2026