9.8
CVSSv3

CVE-2021-36581

Published: 14/09/2021 Updated: 24/09/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kooboo kooboo cms 2.1.1.0

Github Repositories

CVE-2021-36581

CVE-2021-36581 CVE-2021-36581 Vulnerability type: Remote - file upload Insecure file upload in Kooboo CMS 2110 It is possible to upload any file extension to the server The server does not verify the extension of the file and the tester was able to upload an aspx to the server File upload directory: /Content/Kooboo_BinaryResource/UploadFile