← Back to browse · API

CVE-2021-32538

Severity
CRITICAL
CVSS
9.8
EPSS
0.02007
Risk score
39.9
CISA KEV
No
PoC
No
Published
2021-07-07
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2021-19384, GHSA-W9QJ-P795-8XWQ
Products
statamic:CMS unspecified ≤2021/1/8
Sources
euvd EUVD-2021-19384

Description

ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers can upload arbitrary files without logging in, and further execute code unrestrictedly.

References