CVE-2021-39459

HIGH

Redaxo - OS Command Injection

Title source: rule
STIX 2.1

Description

Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute code on the hosting system via a module containing malicious PHP code.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/evildrummer/CVE-2021-XYZ

Scores

CVSS v3 7.2
EPSS 0.1006
EPSS Percentile 93.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
redaxo/redaxo 5.12.1
Published Sep 09, 2021
Tracked Since Feb 18, 2026