Arbitrary Code Execution in SuperMicro-CMS by PCMT
CVE-2021-25857

7.2HIGH

Key Information:

Vendor
CVE Published:
11 August 2023

What is CVE-2021-25857?

A vulnerability in SuperMicro-CMS version 3.11 enables authenticated attackers to exploit the font_type parameter in setup.php, potentially leading to arbitrary code execution. This issue requires an understanding of the platform's structure to exploit effectively. Users of this CMS should ensure they are aware of the risks and take appropriate security measures.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.