File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file upload.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

Mon, 27 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-01-27T17:06:00.696Z

Reserved: 2021-06-07T00:00:00.000Z

Link: CVE-2021-34076

cve-icon Vulnrichment

Updated: 2024-08-04T00:05:52.405Z

cve-icon NVD

Status : Modified

Published: 2023-05-11T12:15:09.070

Modified: 2025-01-27T17:15:08.853

Link: CVE-2021-34076

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.