CVE-2021-37144
Last modified
CVE-2021-37144 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user input might affect portions of or the whole affected parameter, which represents the path of the file to remove, without sufficient sanitization.. EPSS estimates a 1.28% chance of exploitation in the next 30 days.
Description
CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user input might affect portions of or the whole affected parameter, which represents the path of the file to remove, without sufficient sanitization.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cszcms | Csz Cms | 1.2.9 |
References
- https://github.com/cskaza/cszcms/issues/32Exploit, Issue Tracking, Third Party Advisory
- https://github.com/cskaza/cszcms/issues/32Exploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-37144?
How severe is CVE-2021-37144?
How do I fix CVE-2021-37144?
Are you affected by CVE-2021-37144?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
