« Volver al listado

CVE-2021-28428

Estado: ModificadaCrítica (9.8)—

File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media Files upload functionality. The original file upload vulnerability (CVE-2020-27387) was remediated by restricting the PHP extensions; however, we confirmed that the filter was bypassed via uploading an arbitrary .htaccess and *.hello files in order to execute PHP code to gain RCE.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-28428",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-04-05T16:15:11.880",
  "references": [
    {
      "url": "https://github.com/ttimot24/HorizontCMS",
      "tags": [
        "Product"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/ttimot24/HorizontCMS/commit/9c4d6827cbe96decec6834d53660e14ab2bf8838",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/ttimot24/HorizontCMS",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/ttimot24/HorizontCMS/commit/9c4d6827cbe96decec6834d53660e14ab2bf8838",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media Files upload functionality. The original file upload vulnerability (CVE-2020-27387) was remediated by restricting the PHP extensions; however, we confirmed that the filter was bypassed via uploading an arbitrary .htaccess and *.hello files in order to execute PHP code to gain RCE."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad en la carga de archivos en HorizontCMS versiones anteriores a 1.0.0-beta.3, por medio de una carga de archivos .htaccess y *.hello usando la funcionalidad Media Files upload. La vulnerabilidad original en la carga de archivos (CVE-2020-27387) fue corregida al restringir las Extensions de PHP; sin embargo, confirmamos que el filtro fue evitado por medio de la carga de un archivo arbitrario .htaccess y *.hello para ejecutar código PHP y conseguir un RCE"
    }
  ],
  "lastModified": "2026-06-17T03:46:20.220",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0837AB3F-932A-464D-B078-041C1D167681"
            },
            {
              "criteria": "cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "819778BF-D6F0-41DE-ADF2-3BB80E05DD93"
            },
            {
              "criteria": "cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BDF18A37-08AC-4501-8C15-151DE7B44DED"
            },
            {
              "criteria": "cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6F3AB6F-BD6E-4F8C-952F-AB55E11D7D23"
            },
            {
              "criteria": "cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C1817B54-40E9-4150-8A24-2023FD19BB43"
            },
            {
              "criteria": "cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A6585D37-41CF-436A-A4AA-F91AE092D288"
            },
            {
              "criteria": "cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E496572C-0A79-4524-B544-E864FBFEDFD8"
            },
            {
              "criteria": "cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7117177-3CD2-4BE9-982A-FBFEF60A7C23"
            },
            {
              "criteria": "cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB1E6057-C7F5-4D4F-B112-437C801DCCF4"
            },
            {
              "criteria": "cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:beta:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "320BB8EF-D310-4420-9EA9-CA06DFA03DE5"
            },
            {
              "criteria": "cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9840814D-4A55-468B-8F55-EEEE82D7EA29"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}