First published: Wed Jun 30 2021(Updated: )
An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Craftcms Craft Cms | <3.6.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-27903 is critical with a CVSS score of 9.8.
The vulnerability ID for the Craft CMS issue is CVE-2021-27903.
An attacker can exploit CVE-2021-27903 by hijacking an administrator's session and performing unauthorized administrative changes.
The affected software for CVE-2021-27903 is Craft CMS versions up to and including 3.6.7.
To mitigate the vulnerability in Craft CMS, update to version 3.6.7 or higher.