mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-30 18:56:19 +00:00
18 lines
893 B
Markdown
18 lines
893 B
Markdown
### [CVE-2021-42644](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42644)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read through this vulnerability.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://jdr2021.github.io/2021/10/14/CmsEasy_7.7.5_20211012%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E5%86%99%E5%85%A5%E5%92%8C%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E/
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|