{"id":"CVE-2021-39459","details":"Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute code on the hosting system via a module containing malicious PHP code.","modified":"2026-08-22T09:15:35.002947Z","published":"2021-09-09T12:15:09.980Z","references":[{"type":"EVIDENCE","url":"https://github.com/evildrummer/CVE-2021-XYZ"},{"type":"EVIDENCE","url":"https://github.com/evildrummer/MyOwnCVEs/tree/main/CVE-2021-39459"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/redaxo/core","events":[{"introduced":"24afa7042b6d4b1857de46f08efc3a1b06fb0b04"},{"last_affected":"24afa7042b6d4b1857de46f08efc3a1b06fb0b04"}],"database_specific":{"cpe":"cpe:2.3:a:redaxo:redaxo:5.12.1:*:*:*:*:*:*:*","extracted_events":[{"introduced":"5.12.1"},{"last_affected":"5.12.1"}],"source":"CPE_STRING"}}],"versions":["5.12.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-39459.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}