CVE-2021-3164
Summary
| CVE | CVE-2021-3164 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-26 18:16:00 UTC |
| Updated | 2021-02-02 15:29:00 UTC |
| Description | ChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to upload and execute an arbitrary file via a POST request to resources.php. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Churchdesk | Churchrota | 2.6.4 | All | All | All |
| Application | Churchdesk | Churchrota | 2.6.4 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitHub - Little-Ben/ChurchRota: ChurchRota is the web software to simplify the organisation of church rotas, meaning churches spend less time organising and more time doing the mission that God called them into. For a quick start (installation/update instructions) please see README.txt or scroll down. Here is the main place where sources are hosted, feel free to contribute :-) | MISC | github.com | Third Party Advisory |
| GitHub - rmccarth/cve-2021-3164: Church Rota version 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to upload and execute an arbitrary file. The application is written primarily with PHP so we use PHP in our PoC | MISC | github.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.