ZeroHour

CVE-2021-27280

PoC
CVSS 3.1
7.8 high
EPSS
<1%p60
Published
()
Modified
Description

OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected.

Vendors
mblog project
Products
mblog
Weakness
CWE-434
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.