CVE-2021-3376: High severity tina tinacms vulnerability
Published Dec 14, 2021
·Updated
An issue was discovered in Cuppa CMS Versions Before 31 Jan 2021 allows authenticated attackers to gain escalated privileges via a crafted POST request using the usergroupidfield parameter.
Affected Software
1 affected component
CuppaCMS CuppaCMS<31\/jan\/2021
Event History
Dec 14, 2021
CVE Published
via MITRE·01:16 PM
Data Sourced
via MITRE·01:16 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-3376?
CVE-2021-3376 has a medium severity rating due to its potential for privilege escalation.
2
How do I fix CVE-2021-3376?
To fix CVE-2021-3376, upgrade Cuppa CMS to a version released after January 31, 2021.
3
Who is affected by CVE-2021-3376?
Users of Cuppa CMS versions before January 31, 2021 are affected by CVE-2021-3376.
4
What is the impact of CVE-2021-3376?
CVE-2021-3376 allows authenticated attackers to escalate their privileges through a crafted POST request.
5
What specific vulnerability exists in CVE-2021-3376?
CVE-2021-3376 involves improper handling of the user_group_id_field parameter, which can be exploited by authenticated users.