Sploitus Multiple CVEs in Magnolia CMS Expose Users to Remote Code Execution
Article Content
- •Magnolia CMS versions 6.2.3 and below are vulnerable to multiple critical CVEs.
- •Exploitation methods include CSRF, server-side template injection, and YAML deserialization.
- •Patches are available, but PoCs for some vulnerabilities indicate potential for active exploitation.
A series of vulnerabilities affecting Magnolia CMS versions 6.2.3 and below have been disclosed, including CVE-2021-46366, CVE-2021-46362, CVE-2021-46361, and CVE-2021-46364. These vulnerabilities allow unauthorized access and remote code execution through various attack vectors such as CSRF, server-side template injection, and YAML deserialization. The vulnerabilities were published on February 11, 2022, with proof-of-concept (PoC) code for CVE-2021-46364 released on November 24, 2023. Users of affected systems are at risk of credential theft and arbitrary code execution. Vendors have issued advisories for remediation, but the exploitation status varies across the CVEs. Security professionals are urged to apply patches and monitor for signs of exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2021-46361 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…