{ "schema_version": "1.4.0", "id": "GHSA-vhgr-gfx3-fg37", "modified": "2022-04-12T20:35:52Z", "published": "2022-04-01T00:00:41Z", "aliases": [ "CVE-2021-34257" ], "summary": "Unrestricted Upload of File with Dangerous Type in WPanel 4", "details": "Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], "affected": [ { "package": { "ecosystem": "Packagist", "name": "wpanel/wpanel4-cms" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "0" }, { "last_affected": "4.3.1" } ] } ] } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-34257" }, { "type": "WEB", "url": "https://github.com/Sentinal920/WPanel4-Authenticated-RCE" }, { "type": "PACKAGE", "url": "https://github.com/wpanel/wpanel4-cms" }, { "type": "WEB", "url": "https://latestpcsolution.wordpress.com/2021/06/05/wpanel4-cms-authenticated-rce" } ], "database_specific": { "cwe_ids": [ "CWE-434" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-04-12T20:35:52Z", "nvd_published_at": "2022-03-31T16:15:00Z" } }