CVE-2021-39459: OS Command Injection
Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute code on the hosting system via a module containing malicious PHP code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39459?
CVE-2021-39459 is classified as a high severity vulnerability due to the potential for remote code execution.
How does CVE-2021-39459 affect Yakamara Media Redaxo CMS?
CVE-2021-39459 allows an authenticated user to execute malicious PHP code on the hosting system, compromising application security.
Who is affected by CVE-2021-39459?
Any user of Yakamara Media Redaxo CMS version 5.12.1 is at risk due to this vulnerability.
How can I mitigate CVE-2021-39459?
To mitigate CVE-2021-39459, it is recommended to update to a patched version of Yakamara Media Redaxo CMS that addresses this vulnerability.
What are the consequences of exploiting CVE-2021-39459?
Exploiting CVE-2021-39459 can lead to unauthorized access, data compromise, and complete control over the hosting system.