CVE-2021-42675
Kreasfero Remote Code Execution via File Upload Vulnerability
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
Kreasfero's media upload feature has a vulnerability where it does not properly sanitize uploaded files. This could allow an attacker to upload a malicious PHP file and achieve remote code execution on the server. This is a critical issue because it could lead to a complete compromise of the system.