PT-2021-21633 · Rpcms · Rpcms

Zhang Zhiyi

·

Published

2021-07-26

·

Updated

2022-07-12

·

CVE-2021-37394

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RPCMS versions 1.8 and below
Description The issue allows attackers to interact with the API and change the role variable to admin, achieving admin user registration.
Recommendations For RPCMS versions 1.8 and below, as a temporary workaround, consider restricting access to the API endpoint that allows modification of the role variable until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-37394

Affected Products

Rpcms