{"api_version":"1","generated_at":"2026-07-23T12:00:45+00:00","cve":"CVE-2021-3164","urls":{"html":"https://cve.report/CVE-2021-3164","api":"https://cve.report/api/cve/CVE-2021-3164.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-3164","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-3164"},"summary":{"title":"CVE-2021-3164","description":"ChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to upload and execute an arbitrary file via a POST request to resources.php.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-01-26 18:16:00","updated_at":"2021-02-02 15:29:00"},"problem_types":["CWE-434"],"metrics":[],"references":[{"url":"https://github.com/Little-Ben/ChurchRota","name":"https://github.com/Little-Ben/ChurchRota","refsource":"MISC","tags":["Third Party Advisory"],"title":"GitHub - Little-Ben/ChurchRota: ChurchRota is the web software to simplify the organisation of church rotas, meaning churches spend less time organising and more time doing the mission that God called them into. For a quick start (installation/update instructions) please see README.txt or scroll down. Here is the main place where sources are hosted, feel free to contribute :-)","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://github.com/rmccarth/cve-2021-3164","name":"https://github.com/rmccarth/cve-2021-3164","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"GitHub - rmccarth/cve-2021-3164: Church Rota version 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to upload and execute an arbitrary file. The application is written primarily with PHP so we use PHP in our PoC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-3164","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3164","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"3164","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"churchdesk","cpe5":"churchrota","cpe6":"2.6.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"3164","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"churchdesk","cpe5":"churchrota","cpe6":"2.6.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-3164","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"ChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to upload and execute an arbitrary file via a POST request to resources.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/Little-Ben/ChurchRota","refsource":"MISC","name":"https://github.com/Little-Ben/ChurchRota"},{"refsource":"MISC","name":"https://github.com/rmccarth/cve-2021-3164","url":"https://github.com/rmccarth/cve-2021-3164"}]}},"nvd":{"publishedDate":"2021-01-26 18:16:00","lastModifiedDate":"2021-02-02 15:29:00","problem_types":["CWE-434"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:churchdesk:churchrota:2.6.4:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"3164","Ordinal":"200073","Title":"CVE-2021-3164","CVE":"CVE-2021-3164","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"3164","Ordinal":"1","NoteData":"ChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to upload and execute an arbitrary file via a POST request to resources.php.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"3164","Ordinal":"2","NoteData":"2021-01-21","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"3164","Ordinal":"3","NoteData":"2021-01-21","Type":"Other","Title":"Modified"}]}}}