7.5
CVSSv2

CVE-2021-21307

Published: 11/02/2021 Updated: 21/09/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin prior to 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in versions 5.3.7.47, 5.3.6.68 or 5.3.5.96. As a workaround, one can block access to the Lucee Administrator.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lucee lucee server

Exploits

This Metasploit module exploits an arbitrary file write in Lucee Administrator's imgProcesscfm file to execute commands as the Tomcat user ...