Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2021-39172
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
New line injection during configuration edition
Source: NVD (National Vulnerability Database)
Vulnerability Description
Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. This issue was addressed in version 2.5.1 by improving `UpdateConfigCommandHandler` and preventing the use of new lines characters in new configuration values. As a workaround, only allow trusted source IP addresses to access to the administration dashboard.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
对CRLF序列的转义处理不恰当(CRLF注入)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cachet 注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Github Cachet是一个应用软件。一个开源状态页面系统。 Cachet 存在注入漏洞,该漏洞源于在 2.5.1 版本之前,经过身份验证的用户,无论其权限如何(用户或管理员),都可以利用配置版本功能(例如邮件设置)中的新行注入并在服务器上获得任意代码执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
fiveaiCachet < 2.5.1 -
II. Public POCs for CVE-2021-39172
#POC DescriptionSource LinkShenlong Link
1Cachet 2.4 Code Execution via Laravel Configuration Injection CVE-2021-39172https://github.com/W1ngLess/CVE-2021-39172-RCEPOC Details
AI-Generated POCPremium
Qwen3.6-35B-A3B · 8181 chars
Paid plan includes:
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month
III. Intelligence Information for CVE-2021-39172
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2021-39172

No comments yet


Leave a comment