CVE-2021-47936 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: May 10, 2026
OpenCATS - Remote Code Execution
Published: May 10, 2026Updated: May 10, 2026Remote Exploitable
Overview
OpenCATS 0.9.4 contains a remote code execution vulnerability caused by unrestricted file upload of malicious PHP files via the careers job application endpoint, letting unauthenticated attackers execute arbitrary system commands remotely.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Unauthenticated attackers can execute arbitrary system commands, potentially leading to full server compromise.
Mitigation
Update to the latest version of OpenCATS.
References
Related Resources
Details
- CVE ID
- CVE-2021-47936
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- unrestricted_file_upload
- Status
- new
CWE
- CWE-306
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H