Vulnerabilities > CVE-2021-41729 - Missing Authorization vulnerability in Baicloud-Cms Project Baicloud-Cms 2.5.7
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
HIGH Availability impact
HIGH Summary
BaiCloud-cms v2.5.7 is affected by an arbitrary file deletion vulnerability, which allows an attacker to delete arbitrary files on the server through /user/ppsave.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |