CVE-2021-42675
Critical · CVSS 9.8Kreado Kreasfero — Unrestricted File Upload RCE (CWE-434)
- CVSS
- 9.8
- nvd
- EPSS
- 3.10%
- 86th pct
- KEV
- No
- Class
- other
- CWE-434
Description
Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution.
Search profile — drives PoC discovery
Symbols media directoryfile uploadPHP file uploadsanitize uploaded files
Keywords CVE-2021-42675KreasferoKreadoKreasfero 1.5unrestricted file uploadmalicious PHP uploadremote code executionmedia upload RCE
Versions: 1.5
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z