CVE-2021-40189: Malicious File Upload
Published Oct 11, 2021
·Updated
PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/themes/{Theme Folder], where an attacker can access and execute arbitrary code.
Affected Software
1 affected component
PHP-Fusion Phpfusion=9.03.110
Event History
Oct 11, 2021
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-40189.
2
What is the severity of CVE-2021-40189?
The severity of CVE-2021-40189 is high, with a severity value of 7.2.
3
How does CVE-2021-40189 affect PHPFusion?
CVE-2021-40189 affects PHPFusion 9.03.110 by allowing a remote code execution vulnerability.
4
How can an attacker exploit CVE-2021-40189?
An attacker can exploit CVE-2021-40189 by accessing and executing arbitrary code through the file extracted to 'webroot/themes/{Theme Folder]'.
5
Is there a fix for CVE-2021-40189?
At the time of writing, there is no fix available for CVE-2021-40189. It is recommended to update to a version of PHPFusion that is not affected.