Review reviewCritical
CVE-2021-42675
kreasfero
Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution.
- CVSS
- 9.8
- EPSS
- 2.24% 81.1% percentile
- CISA KEV
- Not listed
- Published
- 2022.06.15