CVE-2021-42643

HIGH

cmseasy 7.7.5_20211012 - Arbitrary File Write and Remote Code Execution

Title source: llm
STIX 2.1

Description

cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script file is written to the website server, and accessing this file can lead to a code execution vulnerability.

Scores

CVSS v3 8.8
EPSS 0.0156
EPSS Percentile 72.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (1)
cmseasy/cmseasy 7.7.5_20211012
Published May 17, 2022
Tracked Since Feb 18, 2026