CVE-2021-42183
HIGHMasaCMS 7.2.1 - Path Traversal via /index.cfm/_api/asset/image/
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-42183. PoCs published by 0xRaw.
AI-analyzed exploit summary This repository provides a proof-of-concept for a path traversal vulnerability in MasaCMS 7.2.1, allowing unauthorized file reading via the `/index.cfm/_api/asset/image/` endpoint. The exploit demonstrates reading sensitive files like `Application.cfc` and `settings.ini.cfm` using directory traversal sequences.
Description
MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/.
Exploits (1)
This repository provides a proof-of-concept for a path traversal vulnerability in MasaCMS 7.2.1, allowing unauthorized file reading via the `/index.cfm/_api/asset/image/` endpoint. The exploit demonstrates reading sensitive files like `Application.cfc` and `settings.ini.cfm` using directory traversal sequences.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N