본문 바로가기

Vulnerability Information

CVE-2021-26642 | XpressEngine file upload vulnerability

2023-01-19
□ Overview
 o XEHub Co.,Ltd released security update to address unrestricted upload of file with dangerous type vulnerability in bulletin board developed by XpressEngine.
Vulnerability type Impact Severity CVSS Score CVE ID
Unrestricted upload of file with dangerous type Arbitrary code execution High 8.8 CVE-2021-26642


□ Description
 o When uploading an image file to a bulletin board developed with XpressEngine, a vulnerability in which an arbitrary file can be uploaded due to insufficient verification of the file.
 o A remote attacker can use this vulnerability to execute arbitrary code on the server where the bulletin board is running.

□ Affected Product
Product version Platform
XE3 3.0.14 Windows


□ Solution
 o Update software over XE3 3.0.14 version or higher.

□ Reference
[1] http://github.com/xpressengine/xpressengine/issues/1366

□ Acknowledgements
 o Thanks to Do Hyun Kim for reporting this vulnerability.


□ 작성 : 침해사고분석단 취약점분석팀
Keyword
Top