Auto Generated CVE annotations [Fri Oct 29 12:45:06 UTC 2021] 🤖

patch-1
GitHub Action 2021-10-29 12:45:07 +00:00
parent afbd8f0448
commit 4236ca70b5
1 changed files with 6 additions and 1 deletions

View File

@ -3,13 +3,18 @@ id: CVE-2021-20837
info:
name: CVE-2021-20837
author: dhiyaneshDK
severity: high
severity: critical
description: 5002 and earlier (Movable Type Advanced 7 Series), Movable Type Advanced 6.8. 2 and earlier (Movable Type Advanced 6 Series), Movable Type Premium 1.46 and earlier, and Movable Type Premium Advanced 1.46 and earlier allow remote attackers to execute arbitrary OS commands via unspecified vectors.
reference:
- https://github.com/ghost-nemesis/cve-2021-20837-poc
- https://twitter.com/cyber_advising/status/1454051725904580608/photo/1
tags: cve,cve2021,lfi,rce,misconfig
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.80
cve-id: CVE-2021-20837
cwe-id: CWE-78
requests:
- raw: