CVE-2020-21787: Malicious File Upload
Published Jun 24, 2021
·Updated
CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.
Affected Software
1 affected component
crmeb crmeb=3.1.0\+
Event History
Jun 24, 2021
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
Description
Frequently Asked Questions
1
What is CVE-2020-21787?
CVE-2020-21787 is a vulnerability in CRMEB 3.1.0+ that allows for file upload and shell execution through the /crmeb/crmeb/services/UploadService.php endpoint.
2
How severe is CVE-2020-21787?
CVE-2020-21787 has a severity rating of critical, with a CVSS score of 9.8.
3
What software versions are affected by CVE-2020-21787?
CRMEB versions 3.1.0 and above are affected by CVE-2020-21787.
4
How can I exploit CVE-2020-21787?
To exploit CVE-2020-21787, an attacker can upload malicious files through the /crmeb/crmeb/services/UploadService.php endpoint, allowing them to execute arbitrary code.
5
Is there a fix available for CVE-2020-21787?
At the moment, there is no official fix available for CVE-2020-21787. It is recommended to update to a patched version or apply a security patch if available.