go to Content

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center


ARTWARE CMS - Unrestricted Upload of File

TVN ID TVN-202107001
CVE ID CVE-2021-32538
CVSS 9.8 (Critical)
Affected Products ARTWARE CMS version released before 2021/1/8.
Description ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers can upload arbitrary files without logging in, and further execute code unrestrictedly.
Solution Contact tech support from ARTWARE.
Credit SHENG-FU CHANG (CHT Security Co., Ltd.)
Public Date 2021-07-02