CVE-2021-37270
Last modified
CVE-2021-37270 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0. Attackers can use this vulnerability to directly access the specified background path without logging in to the background to obtain the background administrator authority.. EPSS estimates a 1.44% chance of exploitation in the next 30 days.
Description
There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0. Attackers can use this vulnerability to directly access the specified background path without logging in to the background to obtain the background administrator authority.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| S-Cms | Cms Enterprise Website Construction System | 5.0 |
References
- https://github.com/purple-WL/S-cms-UnauthorizedThird Party Advisory
- https://www.cnvd.org.cn/flaw/show/2815129Third Party Advisory
- https://github.com/purple-WL/S-cms-UnauthorizedThird Party Advisory
- https://www.cnvd.org.cn/flaw/show/2815129Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-37270?
How severe is CVE-2021-37270?
How do I fix CVE-2021-37270?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-37253M-Files Web before 20.10.9524.1 allows a denial of service v…7.5
- CVE-2021-37254In M-Files Web product with versions before 20.10.9524.1 and…7.5
- CVE-2021-3726# Vulnerability in `title` function **Description**: the `ti…9.8
- CVE-2021-37262JFinal_cms 5.1.0 is vulnerable to regex injection that may l…7.5
- CVE-2021-37267Cross Site Scripting (XSS) vulnerability exists in all versi…6.1
- CVE-2021-3727# Vulnerability in `rand-quote` and `hitokoto` plugins **Des…9.8
- CVE-2021-37271Cross Site Scripting (XSS) vulnerability exists in UEditor v…5.4
- CVE-2021-37273A Denial of Service issue exists in China Telecom Corporatio…7.5
- CVE-2021-37274Kingdee KIS Professional Edition has a privilege escalation …8.8
- CVE-2021-3728firefly-iii is vulnerable to Cross-Site Request Forgery (CSR…6.5
- CVE-2021-37289Insecure Permissions in administration interface in Planex M…7.2
- CVE-2021-3729firefly-iii is vulnerable to Cross-Site Request Forgery (CSR…4.3
Are you affected by CVE-2021-37270?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
