Lucene search

K
cvelistMitreCVELIST:CVE-2021-3164
HistoryJan 21, 2021 - 5:45 a.m.

CVE-2021-3164

2021-01-2105:45:20
mitre
www.cve.org
4
churchrota 2.6.4
authenticated
remote code execution
vulnerability
file upload permission
post request
resources.php

AI Score

9.1

Confidence

High

EPSS

0.003

Percentile

71.7%

ChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to upload and execute an arbitrary file via a POST request to resources.php.

AI Score

9.1

Confidence

High

EPSS

0.003

Percentile

71.7%

Related for CVELIST:CVE-2021-3164