HIGH

CVE-2021-43258

CVSS v3

8.8

HIGH

EPSS Score

78.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requires authenticated access tot he ChurchInfo application. Once authenticated, a user can add names to their cart, and compose an email. Uploading an attachment for the email stores the attachment on the site in the /tmp_attach/ folder where it can be accessed with a GET request. There are no limitations on files that can be attached, allowing for malicious PHP code to be uploaded and interpreted by the server.

Technical details

Published
11/23/2022

Frequently asked questions

What is CVE-2021-43258?

CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requires authenticated access tot he ChurchInfo application. Once authenticated, a user can add names to their cart, and compose an email. Uploading an attachment for the email stores the attachment on the site in the /tmp_attach/ folder where it can be accessed with a GET request. There are no limitations on files that can be attached, allowing for malicious PHP code to be uploaded and interpreted by the server.

Is CVE-2021-43258 actively exploited?

Active exploitation of CVE-2021-43258 has not been confirmed. The EPSS score is 78.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-43258?

CVE-2021-43258 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2021-43258 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.