CVE-2021-44912 Information
Jun 07, 2022
cve
Description
In XE 1.116 when uploading the Normal button there is no restriction on the file suffix which leads to any file uploading to the files directory. Since .htaccess only restricts the PHP type uploading HTML-type files leads to stored XSS vulnerabilities. If the .htaccess configuration is improper for example before the XE 1.11.2 version you can upload the PHP type file to GETSHELL.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
https://github.com/xpressengine/xe-core/issues/2433
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: