CVE-2021-23261: Overriding the system configuration file causes a denial of service
Published Dec 2, 2021
·Updated
Authenticated administrators may override the system configuration file and cause a denial of service.
Affected Software
1 affected component
CrafterCMS Crafter Cms>=3.1.0<3.1.13
Event History
Dec 2, 2021
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-23261?
CVE-2021-23261 is a vulnerability that allows authenticated administrators to override the system configuration file and cause a denial of service.
2
What is the severity of CVE-2021-23261?
The severity of CVE-2021-23261 is rated as medium, with a CVSS score of 4.9.
3
How does CVE-2021-23261 affect Crafter CMS?
CVE-2021-23261 affects Crafter CMS version 3.1.0 to 3.1.13. Administrators of these versions are vulnerable to the exploit.
4
Is there a fix available for CVE-2021-23261?
Yes, a fix for CVE-2021-23261 is available. It is recommended to upgrade to a fixed version of Crafter CMS.
5
Where can I find more information about CVE-2021-23261?
You can find more information about CVE-2021-23261 in the security advisory at https://docs.craftercms.org/en/3.1/security/advisory.html#cv-2021120104