CVE-2021-26639

Published Aug 17, 2022

Last updated 2 years ago

Overview

Description
This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this vulnerability to leak all files in the server without logging in system.
Source
vuln@krcert.or.kr
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Weaknesses

nvd@nist.gov
CWE-20
vuln@krcert.or.kr
CWE-20

Social media

Hype score
Not currently trending

Configurations