VulnerabilityModified
CVE-2021-37770
Nucleus CMS v3.71 is affected by a file upload vulnerability.
HIGH 7.2EPSS 1.29%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.29%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Nucleus CMS v3.71 is affected by a file upload vulnerability. In this vulnerability, we can use upload to change the upload path to the path without the Htaccess file. Upload an Htaccess file and write it to AddType application / x-httpd-php.jpg. In this way, an attacker can upload a picture with shell, treat it as PHP, execute commands, so as to take down website resources.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.29% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- nucleuscms/nucleus cms
- Source
- cve@mitre.org
References
- https://github.com/NucleusCMS/NucleusCMS/issues/96Exploit, Issue Tracking, Third Party Advisory
- https://shimo.im/docs/Ch9CphJt8XwTvQ3dExploit, Third Party Advisory
- https://github.com/NucleusCMS/NucleusCMS/issues/96Exploit, Issue Tracking, Third Party Advisory
- https://shimo.im/docs/Ch9CphJt8XwTvQ3dExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.