Vulnerability Details CVE-2021-20721
KonaWiki2 versions prior to 2.2.4 allows a remote attacker to upload arbitrary files via unspecified vectors. If the file contains PHP scripts, arbitrary code may be executed.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 70.5%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2021-20721
-
cpe:2.3:a:kujirahand:konawiki:2.1.0
-
cpe:2.3:a:kujirahand:konawiki:2.1.0.1
-
cpe:2.3:a:kujirahand:konawiki:2.1.0.2
-
cpe:2.3:a:kujirahand:konawiki:2.2.0