First published: Wed Dec 01 2021(Updated: )
Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage. The groovy script does not have security restrictions, which will cause attackers to execute arbitrary commands remotely(RCE).
Credit: security@craftersoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Craftercms Crafter Cms | >=3.1.0<3.1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23259 is a vulnerability in Crafter CMS that allows authenticated users with Administrator or Developer roles to execute arbitrary OS commands through a Groovy Script.
Attackers can exploit CVE-2021-23259 by using a Groovy Script in Crafter CMS to execute arbitrary OS commands remotely.
CVE-2021-23259 has a severity rating of 7.2 (High).
Crafter CMS versions between 3.1.0 and 3.1.12 are affected by CVE-2021-23259.
To fix CVE-2021-23259, update your Crafter CMS installation to a version higher than 3.1.12.