Vulnerability Details CVE-2021-42342
An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted environment variables into vulnerable CGI scripts.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.773
EPSS Ranking 98.9%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2021-42342
-
cpe:2.3:a:embedthis:goahead:4.0.0
-
cpe:2.3:a:embedthis:goahead:4.0.1
-
cpe:2.3:a:embedthis:goahead:4.0.2
-
cpe:2.3:a:embedthis:goahead:4.1.0
-
cpe:2.3:a:embedthis:goahead:4.1.1
-
cpe:2.3:a:embedthis:goahead:4.1.2
-
cpe:2.3:a:embedthis:goahead:4.1.3
-
cpe:2.3:a:embedthis:goahead:5.0.0
-
cpe:2.3:a:embedthis:goahead:5.0.1
-
cpe:2.3:a:embedthis:goahead:5.1.0
-
cpe:2.3:a:embedthis:goahead:5.1.2
-
cpe:2.3:a:embedthis:goahead:5.1.3
-
cpe:2.3:a:embedthis:goahead:5.1.4