CVE-2021-38243: Code Injection
Published Sep 26, 2023
·Updated
xunruicms <=4.5.1 is vulnerable to Remote Code Execution.
Other sources
xunruicms up to v4.5.1 was discovered to contain a remote code execution (RCE) vulnerability in /index.php. This vulnerability allows attackers to execute arbitrary code via a crafted GET request.
— MITRE
Affected Software
1 affected component
XunRuiCMS XunRuiCMS<=4.5.1
Event History
Sep 26, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Sep 27, 2023
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for xunruicms <=4.5.1?
The vulnerability ID for xunruicms <=4.5.1 is CVE-2021-38243.
2
What is the severity of CVE-2021-38243?
The severity of CVE-2021-38243 is critical.
3
What is the affected software for CVE-2021-38243?
The affected software for CVE-2021-38243 is xunruicms version up to and including 4.5.1.
4
What type of vulnerability is CVE-2021-38243?
CVE-2021-38243 is a vulnerability that allows remote code execution.
5
Is there a fix available for CVE-2021-38243?
At the moment, there is no official fix available for CVE-2021-38243. It is recommended to update to a patched version when it becomes available.