CVE-2021-39458
6.5 MEDIUMTriggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user has to altern...
Published: 2021-09-09 · Last updated: 2026-06-17
Severity and scoring
- CVSS
- 6.5 MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- CWE
- CWE-209
Affected products
| Vendor | Product |
|---|---|
| redaxo | redaxo |
Description
Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user has to alternate the files of a vaild file backup. This leads of leaking the database credentials in the environment variables.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2021-39458
- [Exploit reference]https://github.com/evildrummer/CVE-2021-XYZ2
- [Exploit reference]https://github.com/evildrummer/MyOwnCVEs/tree/main/CVE-2021-39458
- [Exploit reference]https://github.com/evildrummer/CVE-2021-XYZ2
- [Exploit reference]https://github.com/evildrummer/MyOwnCVEs/tree/main/CVE-2021-39458
Related CVEs
Same vendor
- CVE-2021-39459 — Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute co... (7.2 HIGH)
Same CWE
- CVE-2026-47248 — Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js
- CVE-2026-40997 — Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semant... (5.3 MEDIUM)
- CVE-2026-41730 — Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer intern... (5.3 MEDIUM)
- CVE-2025-52611 — HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability (3.1 LOW)
- CVE-2025-52606 — HCL iControl was affected by Weak Input Validation vulnerability (4.3 MEDIUM)