CVE-2021-26639

This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this vulnerability to leak all files in the server without logging in system.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:wisa:smart_wing_cms:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:56

Type Values Removed Values Added
References () https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66875 - Third Party Advisory () https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66875 - Third Party Advisory
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 8.1

Information

Published : 2022-08-17 21:15

Updated : 2024-11-21 05:56


NVD link : CVE-2021-26639

Mitre link : CVE-2021-26639

CVE.ORG link : CVE-2021-26639


JSON object : View

Products Affected

linux

  • linux_kernel

wisa

  • smart_wing_cms
CWE
CWE-20

Improper Input Validation

CWE-494

Download of Code Without Integrity Check