578
VMScore

CVE-2021-39271

Published: 30/08/2021 Updated: 02/09/2021
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

OrbiTeam BSCW Classic prior to 7.4.3 allows authenticated remote code execution (RCE) during archive extraction via attacker-supplied Python code in the class attribute of a .bscw file. This is fixed in 5.0.12, 5.1.10, 5.2.4, 7.3.3, and 7.4.3.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bscw bscw classic

Exploits

BSCW Server versions 742 and below, 732 and below, 523 and below, 519 and below, and 5011 and below suffer from an authenticated remote code execution vulnerability ...