{"id":"CVE-2021-28428","details":"File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media Files upload functionality. The original file upload vulnerability (CVE-2020-27387) was remediated by restricting the PHP extensions; however, we confirmed that the filter was bypassed via uploading an arbitrary .htaccess and *.hello files in order to execute PHP code to gain RCE.","modified":"2026-08-27T03:48:40.713663838Z","published":"2022-04-05T16:15:11.880Z","database_specific":{"unresolved_ranges":[{"vendor_product":"horizontcms_project:horizontcms","cpes":["cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha2:*:*:*:*:*:*","cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha3:*:*:*:*:*:*","cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha4:*:*:*:*:*:*","cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha5:*:*:*:*:*:*","cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha6:*:*:*:*:*:*","cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha7:*:*:*:*:*:*","cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha8:*:*:*:*:*:*","cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:beta2:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.0.0-alpha2"},{"last_affected":"1.0.0-alpha2"},{"introduced":"1.0.0-alpha3"},{"last_affected":"1.0.0-alpha3"},{"introduced":"1.0.0-alpha4"},{"last_affected":"1.0.0-alpha4"},{"introduced":"1.0.0-alpha5"},{"last_affected":"1.0.0-alpha5"},{"introduced":"1.0.0-alpha6"},{"last_affected":"1.0.0-alpha6"},{"introduced":"1.0.0-alpha7"},{"last_affected":"1.0.0-alpha7"},{"introduced":"1.0.0-alpha8"},{"last_affected":"1.0.0-alpha8"},{"introduced":"1.0.0-beta2"},{"last_affected":"1.0.0-beta2"}],"source":"CPE_STRING"}]},"references":[{"type":"FIX","url":"https://github.com/ttimot24/HorizontCMS/commit/9c4d6827cbe96decec6834d53660e14ab2bf8838"},{"type":"PACKAGE","url":"https://github.com/ttimot24/HorizontCMS"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ttimot24/horizont-cms","events":[{"introduced":"3b09e6fbddf193fbd904b9f0cb72dc9dda252001"},{"last_affected":"5aa34ac4e457a49b83f24a2969593c495f3ed9ad"},{"fixed":"9c4d6827cbe96decec6834d53660e14ab2bf8838"}],"database_specific":{"cpe":["cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:-:*:*:*:*:*:*","cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:alpha:*:*:*:*:*:*","cpe:2.3:a:horizontcms_project:horizontcms:1.0.0:beta:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.0.0-NA"},{"last_affected":"1.0.0-NA"},{"introduced":"1.0.0-alpha"},{"last_affected":"1.0.0-alpha"},{"introduced":"1.0.0-beta"},{"last_affected":"1.0.0-beta"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["1.0.0-NA","1.0.0-alpha","1.0.0-beta"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-28428.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}