CVE-2021-37394

Published
View on NVD ↗
CVSS v3
8.8
HIGH
CVSS v2
6
MEDIUM
Affected
1
PROJECT

Description

In RPCMS v1.8 and below, attackers can interact with API and change variable "role" to "admin" to achieve admin user registration.

RPCMS内容管理系统
GitHubGitHub
4