Beveiligingsadvies

CVE-2021-3164

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-01-21 05:45:20
Laatst bijgewerkt 2024-08-03 16:45:51
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

ChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to upload and execute an arbitrary file via a POST request to resources.php.