CVE-2021-28377 is a Directory Traversal vulnerability affecting ChronoForums version 2.0.11, allowing an unauthenticated attacker to read arbitrary files on the server. Rated as Medium severity (CVSS 5.3), this vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, potentially leading to information disclosure. While not currently listed on CISA's KEV catalog and lacking public exploit code on Metasploit or ExploitDB, a Nuclei template for Local File Inclusion exists. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.11CPE matchmatch criteria | cpe:2.3:a:chronoengine:chronoforums:2.0.11:*:*:*:*:joomla:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.