Vulnerability Details CVE-2021-20104
Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded with forms through upload.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.013
EPSS Ranking 78.8%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 6.8
Products affected by CVE-2021-20104
-
cpe:2.3:a:machform:machform:13
-
cpe:2.3:a:machform:machform:14
-
cpe:2.3:a:machform:machform:15
-
cpe:2.3:a:machform:machform:2.0
-
cpe:2.3:a:machform:machform:3.5
-
cpe:2.3:a:machform:machform:4.2.3