PT-2021-17657 · Craft Cms · Craft Cms

Published

2021-06-30

·

Updated

2022-07-12

·

CVE-2021-27903

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Craft CMS versions prior to 3.6.7
Description: A potential Remote Code Execution issue existed in certain circumstances on sites that did not restrict administrative changes, particularly if an attacker could hijack an administrator's session.
Recommendations: For versions prior to 3.6.7, update to version 3.6.7 or later to resolve the issue. As a temporary workaround, consider restricting administrative changes and ensuring session security to minimize the risk of exploitation.

Fix

RCE

Code Injection

Missing Authorization

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27903
GHSA-X2J7-6HXM-87P3

Affected Products

Craft Cms