CVE-2021-27903: Code Injection
Published Jun 30, 2021
·Updated
An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).
Affected Software
2 affected componentsFixes available
composer/craftcms/cms<3.6.7
3.6.7
Craft CMS<3.6.7
Remediation
Event History
Jun 30, 2021
CVE Published
via MITRE·11:56 AM
Data Sourced
via MITRE·11:56 AM
Description
Jul 2, 2021
Advisory Published
06:36 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-27903?
The severity of CVE-2021-27903 is critical with a CVSS score of 9.8.
2
What is the vulnerability ID for the Craft CMS issue?
The vulnerability ID for the Craft CMS issue is CVE-2021-27903.
3
How can an attacker exploit CVE-2021-27903?
An attacker can exploit CVE-2021-27903 by hijacking an administrator's session and performing unauthorized administrative changes.
4
What is the affected software for CVE-2021-27903?
The affected software for CVE-2021-27903 is Craft CMS versions up to and including 3.6.7.
5
How do I mitigate the vulnerability in Craft CMS?
To mitigate the vulnerability in Craft CMS, update to version 3.6.7 or higher.