CVE-2021-23259

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/12/2021
Last modified:
03/12/2021

Description

Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage. The groovy script does not have security restrictions, which will cause attackers to execute arbitrary commands remotely(RCE).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:craftercms:crafter_cms:*:*:*:*:*:*:*:* 3.1.0 (including) 3.1.12 (excluding)