60
CVE-2021-34816
PoC —CVSS 3.1
7.2 high
EPSS
2%p82
Published
()
Modified
Description
An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by installing plugins from an attacker-controlled source.
- Vendors
- etherpad
- Products
- etherpad
- Weakness
- CWE-88
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H