Vulnerability Details CVE-2021-42342
An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted environment variables into vulnerable CGI scripts.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.826
EPSS Ranking 99.2%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2021-42342
-
cpe:2.3:a:embedthis:goahead:4.0.0
-
cpe:2.3:a:embedthis:goahead:4.0.1
-
cpe:2.3:a:embedthis:goahead:4.0.2
-
cpe:2.3:a:embedthis:goahead:4.1.0
-
cpe:2.3:a:embedthis:goahead:4.1.1
-
cpe:2.3:a:embedthis:goahead:4.1.2
-
cpe:2.3:a:embedthis:goahead:4.1.3
-
cpe:2.3:a:embedthis:goahead:5.0.0
-
cpe:2.3:a:embedthis:goahead:5.0.1
-
cpe:2.3:a:embedthis:goahead:5.1.0
-
cpe:2.3:a:embedthis:goahead:5.1.2
-
cpe:2.3:a:embedthis:goahead:5.1.3
-
cpe:2.3:a:embedthis:goahead:5.1.4