CVE-2021-46367
HIGHRiteCMS <3.1.0 - RCE
Title source: llmDescription
RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can upload a PHP file and bypass the .htacess configuration to deny execution of .php files in media and files directory by default.
Exploits (1)
References (4)
Scores
CVSS v3
7.2
EPSS
0.2471
EPSS Percentile
96.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (1)
ritecms/ritecms
< 3.1.0
Published
Apr 08, 2022
Tracked Since
Feb 18, 2026