PT-2021-21633 · Rpcms · Rpcms
Zhang Zhiyi
·
Published
2021-07-26
·
Updated
2022-07-12
·
CVE-2021-37394
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RPCMS versions 1.8 and below
Description
The issue allows attackers to interact with the API and change the
role variable to admin, achieving admin user registration.Recommendations
For RPCMS versions 1.8 and below, as a temporary workaround, consider restricting access to the API endpoint that allows modification of the
role variable until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rpcms