S4E just found a low-severity finding from [ai] web application external link detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-32172 Scanner

CVE-2021-32172 scanner - Remote Code Execution (RCE) vulnerability in Maian Cart

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-32172
9.8
CVSS

Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Maian Cart v3.8 is an open-source e-commerce platform that enables businesses to set up an online store and sell their products or services. The software also provides the functionality for customers to view and purchase items, manage their accounts, and receive order notifications. With a user-friendly interface and a range of customizable features, Maian Cart has become a popular choice for small and medium-sized businesses looking to establish an online presence. 

Unfortunately, the software was recently found to contain a serious vulnerability, known as CVE-2021-32172. This vulnerability allows attackers to execute code remotely, due to a broken access control issue in the Elfinder plugin. As a result, cybercriminals can gain unauthorized access to sensitive information and potentially take control of the affected system. 

If exploited, this vulnerability can lead to significant damage. Attackers can steal sensitive information such as personal data, financial records, and customer details, causing significant financial loss and reputational damage. Additionally, they can use the compromised system to launch further attacks on other systems, amplifying the damage caused even further. 

At s4e.io, we provide a range of pro features that enable users to quickly and easily detect vulnerabilities in their digital assets. By subscribing to our platform, users can monitor their systems for potential threats and receive real-time alerts when issues arise. With our advanced tools and expert support, businesses can rest assured that their online assets are secure and protected from harm. By taking the right precautions and leveraging the latest technologies, we can help our customers stay one step ahead of cybercriminals and protect their digital assets from harm.

 

REFERENCES

Solution Advice

To protect against this vulnerability, Maian Cart users can take several precautions, including:

  • Updating to the latest version of the software, which includes a fix for the vulnerability 
  • Disabling the Elfinder plugin until a patch is available 
  • Using firewalls and other security measures to prevent unauthorized access to the system 
  • Ensuring that all user accounts have strong, unique passwords 
  • Regularly monitoring system logs for suspicious activity. 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-32172 scanner - Remote Code Execution (RCE) vulnerability in Maian Cart | S4E