CVE detail
CVE-2021-26634 — CVE-2021-26634
Published 2022-06-02 · Modified 2026-06-17 · Vendor maxb · Product maxboard · Source nvd
CRITICAL
severity
CVSS-derived band
0.0125
EPSS probability
exploitation probability, 30d
67.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and variables of files compromising Maxboard, which may lead to arbitrary code execution or privilege escalation. Attackers can use these vulnerabilities to perform attacks such as stealing server management rights using a web shell.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References