ZeroHour

CVE-2021-34816

PoC
CVSS 3.1
7.2 high
EPSS
2%p82
Published
()
Modified
Description

An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by installing plugins from an attacker-controlled source.

Vendors
etherpad
Products
etherpad
Weakness
CWE-88
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news