CVE-2021-43852 is a prototype pollution vulnerability affecting OroPlatform, a PHP Business Application Platform. An unauthenticated attacker can inject properties into JavaScript prototypes via a specially crafted request, potentially leading to remote code execution. This vulnerability carries a high CVSS score of 8.8, indicating a severe risk with high impact on confidentiality, integrity, and availability, requiring user interaction to exploit. While no public exploits or active exploitation have been observed, and community discussion is minimal, users are advised to upgrade to version 4.2.8 or implement firewall rules to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.1.0, < 4.1.14CPE matchmatch criteria | cpe:2.3:a:oroinc:oroplatform:*:*:*:*:*:*:*:* | ||
>= 4.2.0, < 4.2.8CPE matchmatch criteria | cpe:2.3:a:oroinc:oroplatform:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.