ID

VAR-202212-1427


CVE

CVE-2021-4226


TITLE

rsjoomla  of  WordPress  for  rsfirewall!  Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2022-025204

DESCRIPTION

RSFirewall tries to identify the original IP address by looking at different HTTP headers. A bypass is possible due to the way it is implemented. rsjoomla of WordPress for rsfirewall! Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.8

sources: NVD: CVE-2021-4226 // JVNDB: JVNDB-2022-025204 // VULHUB: VHN-419290 // VULMON: CVE-2021-4226

AFFECTED PRODUCTS

vendor:rsjoomlamodel:rsfirewall\!scope:ltversion:1.1.25

Trust: 1.0

vendor:rsjoomlamodel:rsfirewall!scope:eqversion: -

Trust: 0.8

vendor:rsjoomlamodel:rsfirewall!scope:eqversion:1.1.25

Trust: 0.8

vendor:rsjoomlamodel:rsfirewall!scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-025204 // NVD: CVE-2021-4226

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-4226
value: CRITICAL

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2021-4226
value: CRITICAL

Trust: 1.0

NVD: CVE-2021-4226
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-202212-3314
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2021-4226
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 2.0

NVD: CVE-2021-4226
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-025204 // CNNVD: CNNVD-202212-3314 // NVD: CVE-2021-4226 // NVD: CVE-2021-4226

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-345

Trust: 1.0

problemtype:CWE-639

Trust: 0.1

sources: VULHUB: VHN-419290 // NVD: CVE-2021-4226

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202212-3314

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202212-3314

PATCH

title:WordPress plugin RSFirewall 1.1.25 Security vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=218505

Trust: 0.6

sources: CNNVD: CNNVD-202212-3314

EXTERNAL IDS

db:NVDid:CVE-2021-4226

Trust: 3.4

db:JVNDBid:JVNDB-2022-025204

Trust: 0.8

db:CNNVDid:CNNVD-202212-3314

Trust: 0.6

db:VULHUBid:VHN-419290

Trust: 0.1

db:VULMONid:CVE-2021-4226

Trust: 0.1

sources: VULHUB: VHN-419290 // VULMON: CVE-2021-4226 // JVNDB: JVNDB-2022-025204 // CNNVD: CNNVD-202212-3314 // NVD: CVE-2021-4226

REFERENCES

url:https://wpscan.com/vulnerability/c0ed80c8-ebbf-4ed9-b02f-31660097c352

Trust: 2.6

url:https://nvd.nist.gov/vuln/detail/cve-2021-4226

Trust: 1.4

url:https://cxsecurity.com/cveshow/cve-2021-4226/

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/639.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-419290 // VULMON: CVE-2021-4226 // JVNDB: JVNDB-2022-025204 // CNNVD: CNNVD-202212-3314 // NVD: CVE-2021-4226

SOURCES

db:VULHUBid:VHN-419290
db:VULMONid:CVE-2021-4226
db:JVNDBid:JVNDB-2022-025204
db:CNNVDid:CNNVD-202212-3314
db:NVDid:CVE-2021-4226

LAST UPDATE DATE

2025-05-28T23:20:52.304000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-419290date:2022-12-20T00:00:00
db:VULMONid:CVE-2021-4226date:2022-12-15T00:00:00
db:JVNDBid:JVNDB-2022-025204date:2024-08-09T05:48:00
db:CNNVDid:CNNVD-202212-3314date:2022-12-21T00:00:00
db:NVDid:CVE-2021-4226date:2025-05-27T21:06:17.210

SOURCES RELEASE DATE

db:VULHUBid:VHN-419290date:2022-12-15T00:00:00
db:VULMONid:CVE-2021-4226date:2022-12-15T00:00:00
db:JVNDBid:JVNDB-2022-025204date:2024-08-09T00:00:00
db:CNNVDid:CNNVD-202212-3314date:2022-12-15T00:00:00
db:NVDid:CVE-2021-4226date:2022-12-15T19:15:16.410