CVE-2021-36573: XSS
Published Dec 15, 2022
·Updated
File Upload vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via crafted image upload.
Affected Software
1 affected component
Feehi Feehicms<=2.1.1
Event History
Dec 15, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-36573?
CVE-2021-36573 has a high severity rating as it allows attackers to execute arbitrary code through a file upload vulnerability.
2
How do I fix CVE-2021-36573?
To fix CVE-2021-36573, upgrade Feehi CMS to version 2.1.2 or later which addresses this vulnerability.
3
What types of attacks are possible with CVE-2021-36573?
CVE-2021-36573 can lead to remote code execution attacks, allowing unauthorized actions on the server.
4
Which versions of Feehi CMS are affected by CVE-2021-36573?
Feehi CMS versions up to and including 2.1.1 are affected by CVE-2021-36573.
5
Is CVE-2021-36573 easy to exploit?
Yes, CVE-2021-36573 is considered easy to exploit due to improper validation of file uploads.