PT-2021-17033 · Unknown · Smartfoxserver

Published

2021-02-09

·

Updated

2021-02-18

·

CVE-2021-26551

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SmartFoxServer version 2.17.0
Description An issue allows an attacker to execute arbitrary Python code and bypass the javashell.py protection mechanism. This can be achieved by creating a file named /config/ConsoleModuleUnlock.txt and editing the /config/admin/admintool.xml file to enable the Console module.
Recommendations For SmartFoxServer version 2.17.0, consider disabling the Console module until a patch is available to prevent exploitation. Restrict access to the /config/ConsoleModuleUnlock.txt and /config/admin/admintool.xml files to minimize the risk of unauthorized modifications.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-26551

Affected Products

Smartfoxserver