File Deletion Vulnerability in SuperMicro-CMS by PCMT
CVE-2021-25856

4.9MEDIUM

Key Information:

Vendor
CVE Published:
11 August 2023

What is CVE-2021-25856?

A vulnerability in SuperMicro-CMS version 3.11 allows attackers to delete files by uploading specially crafted image files through the images.php component. This flaw can lead to unauthorized file access and potential data loss, posing a significant threat to the integrity of the web application.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-25856 : File Deletion Vulnerability in SuperMicro-CMS by PCMT