QSearchQSearch

CVE-2021-39458

6.5 MEDIUM

Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user has to altern...

Published: 2021-09-09 · Last updated: 2026-06-17

Severity and scoring

CVSS
6.5 MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE
CWE-209

Affected products

VendorProduct
redaxoredaxo

Description

Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user has to alternate the files of a vaild file backup. This leads of leaking the database credentials in the environment variables.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2021-39459 Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute co... (7.2 HIGH)

Same CWE

  • CVE-2026-47248 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js
  • CVE-2026-40997 Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semant... (5.3 MEDIUM)
  • CVE-2026-41730 Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer intern... (5.3 MEDIUM)
  • CVE-2025-52611 HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability (3.1 LOW)
  • CVE-2025-52606 HCL iControl was affected by Weak Input Validation vulnerability (4.3 MEDIUM)