CVE-2021-33199 is a critical vulnerability affecting Expression Engine before version 6.0.3, where the addonIcon function in mod.file.php improperly uses untrusted user input for file names instead of fixed values. This flaw carries a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, the vulnerability has garnered significant community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.0.3CPE matchmatch criteria | cpe:2.3:a:expressionengine:expressionengine:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.