Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-25294

OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php calls unserialize for the parametersactivity:ActivityDataGrid parameter. The PHP object injection exploit chain can leverage an __destruct magic method in guzzlehttp.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.277
EPSS Ranking 96.2%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2021-25294


Contact Us

Shodan ® - All rights reserved