VYPR
Critical severity9.8NVD Advisory· Published Apr 5, 2022· Updated Jun 17, 2026

CVE-2021-28428

CVE-2021-28428

Description

File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media Files upload functionality. The original file upload vulnerability (CVE-2020-27387) was remediated by restricting the PHP extensions; however, we confirmed that the filter was bypassed via uploading an arbitrary .htaccess and *.hello files in order to execute PHP code to gain RCE.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

13
  • HorizontCMS/HorizontCMSdescription
  • cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:-:*:*:*:*:*:*+ 10 more
    • cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:-:*:*:*:*:*:*
    • cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha:*:*:*:*:*:*
    • cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha2:*:*:*:*:*:*
    • cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha3:*:*:*:*:*:*
    • cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha4:*:*:*:*:*:*
    • cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha5:*:*:*:*:*:*
    • cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha6:*:*:*:*:*:*
    • cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha7:*:*:*:*:*:*
    • cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha8:*:*:*:*:*:*
    • cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:beta:*:*:*:*:*:*
    • cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:beta2:*:*:*:*:*:*
  • Range: <1.0.0-beta.3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.