NVD disclosure day

Published threat advisories for September 14, 2021

CVE advisoryCRITICAL

CVE-2021-36582

Kooboo CMS Remote Code Execution via File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Kooboo CMS vulnerability allows unauthenticated attackers to upload and execute a remote shell on the server, enabling full server compromise and control via a reverse shell. This issue is reachable over the network and could expose sensitive data or disrupt operations.

CVE advisoryCRITICAL

CVE-2021-36581

Kooboo CMS Insecure File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Kooboo CMS is susceptible to insecure file uploads, allowing any file extension, including malicious ones, to be uploaded to the server without proper validation. This could lead to arbitrary code execution on the server, impacting the confidentiality, integrity, and availability of systems and data. Due to its network