CVE-2021-39459

HIGH

Redaxo CMS 5.12.1 - Authenticated Remote Code Execution via Malicious Module

Title source: llm
STIX 2.1

Description

Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute code on the hosting system via a module containing malicious PHP code.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/evildrummer/CVE-2021-XYZ

Scores

CVSS v3 7.2
EPSS 0.0455
EPSS Percentile 90.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
redaxo/redaxo 5.12.1
Published Sep 09, 2021
Tracked Since Feb 18, 2026