CVE-2021-37770
Dashboard / Vulnerabilities / CVE-2021-37770
CVE-2021-37770
Published: 30 Jun 2022Last Modified: 10 Mar 2026
Summary:
Details: Nucleus CMS v3.71 is affected by a file upload vulnerability. In this vulnerability, we can use upload to change the upload path to the path without the Htaccess file. Upload an Htaccess file and write it to AddType application / x-httpd-php.jpg. In this way, an attacker can upload a picture with shell, treat it as PHP, execute commands, so as to take down website resources.
References: , https://github.com/NucleusCMS/NucleusCMS/issues/96, https://shimo.im/docs/Ch9CphJt8XwTvQ3d
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
