PT-2021-19781 · Unknown · Kuaifancms

Ztxyzwd

·

Published

2021-06-11

·

Updated

2021-06-23

·

CVE-2021-3256

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions KuaiFanCMS versions 5.x
Description The issue is related to an arbitrary file read vulnerability. It is located in the html url parameter of the chakanhtml.module.php file.
Recommendations For KuaiFanCMS versions 5.x, avoid using the html url parameter in the chakanhtml.module.php file until a fix is available. Consider restricting access to the chakanhtml.module.php file to minimize the risk of exploitation.

Exploit

Fix

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3256

Affected Products

Kuaifancms