CVE-2021-27903

CRITICAL9.8EPSS 3.8%

Craft CMS Remote Code Injection

Published: 7/2/2021Modified: 2/16/2024
Also known as:GHSA-x2j7-6hxm-87p3

Description

An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (4)