VYPR
Critical severity9.8NVD Advisory· Published Sep 14, 2021· Updated Jul 9, 2026

CVE-2021-36581

CVE-2021-36581

Description

Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Kooboo/CMS2 versions
    cpe:2.3:a:kooboo:kooboo_cms:2.1.1.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:kooboo:kooboo_cms:2.1.1.0:*:*:*:*:*:*:*
    • (no CPE)range: =2.1.1.0
  • Kooboo/Kooboo CMSdescription

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.