CVE-2021-42654: Malicious File Upload
Published May 24, 2022
·Updated
SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.
Affected Software
1 affected component
sscms Siteserver Cms<5.1
Remediation
Event History
May 24, 2022
CVE Published
via MITRE·12:41 PM
Data Sourced
via MITRE·12:41 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-42654.
2
What is the severity of CVE-2021-42654?
The severity of CVE-2021-42654 is critical.
3
What is the affected version of SiteServer CMS?
The affected version of SiteServer CMS is < V5.1.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by uploading a file with a dangerous type, which can be used to execute arbitrary code.
5
Is there a fix available for CVE-2021-42654?
Yes, a fix is available for CVE-2021-42654. It is recommended to update to version 5.1 or later of SiteServer CMS.