Summary
Detail | |||
---|---|---|---|
Vendor | Redaxo | First view | 2021-09-09 |
Product | Redaxo | Last view | 2021-09-09 |
Version | 5.12.1 | Type | Application |
Update | * | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:redaxo:redaxo |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
7.2 | 2021-09-09 | CVE-2021-39459 | Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute code on the hosting system via a module containing malicious PHP code. |
6.5 | 2021-09-09 | CVE-2021-39458 | Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user has to alternate the files of a vaild file backup. This leads of leaking the database credentials in the environment variables. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
50% (1) | CWE-209 | Information Exposure Through an Error Message |
50% (1) | CWE-78 | Improper Sanitization of Special Elements used in an OS Command ('O... |