ZeroHour

CVE-2021-39458

PoC ×2
CVSS 3.1
6.5 medium
EPSS
1%p66
Published
()
Modified
Description

Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user has to alternate the files of a vaild file backup. This leads of leaking the database credentials in the environment variables.

Vendors
redaxo
Products
redaxo
Weakness
CWE-209
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.