CVE-2021-42675

Publication date

2022-06-14 16:29:42

Family

mitre

State

PUBLISHED

Description

Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution.