CVE-2021-27693: SSRF
Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-27693?
CVE-2021-27693 is a Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.
How severe is CVE-2021-27693?
CVE-2021-27693 has a severity rating of 9.8, which is considered critical.
What is the affected software?
The affected software is PublicCMS before version 4.0.202011.b.
How can I fix CVE-2021-27693?
To fix CVE-2021-27693, you should upgrade PublicCMS to version 4.0.202011.b or later.
Is there any additional information available?
Yes, you can find more information about CVE-2021-27693 in the references section: [GitHub Commit](https://github.com/sanluan/PublicCMS/commit/0f4c4872914b6a71305e121a7d9a19c07cde0338) and [GitHub Issue](https://github.com/sanluan/PublicCMS/issues/51).