Skip to main content
CRITICAL

CVE-2021-41646

CVSS v3

9.8

CRITICAL

EPSS Score

3.7 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters..

Technical details

Published
2021-10-29

Frequently asked questions

What is CVE-2021-41646?

Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters..

Is CVE-2021-41646 actively exploited?

Active exploitation of CVE-2021-41646 has not been confirmed. The EPSS score is 3.7%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-41646?

CVE-2021-41646 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2021-41646 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key