CVE-2021-23259
02.12.2021, 16:15
Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage. The groovy script does not have security restrictions, which will cause attackers to execute arbitrary commands remotely(RCE).Enginsight
Vendor | Product | Version |
---|---|---|
craftercms | crafter_cms | 3.1.0 ≤ 𝑥 < 3.1.12 |
𝑥
= Vulnerable software versions