KEVIntel
8.6
CVSS
High

CVE-2021-21307

PUBLISHED

Remote Code Exploit in Lucee Admin

Exploited in the wild Remote Low complexity No user interaction
Vendor
lucee
Product
Lucee
Published
Feb 11, 2021
EPSS

Description

Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in versions 5.3.7.47, 5.3.6.68 or 5.3.5.96. As a workaround, one can block access to the Lucee Administrator.

java nuclei_scanner metasploit

CVSS scores

CVSS v3.1 8.6 High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Exploitation status

Exploited in the wild

Recorded 2025-04-22 00:00:00 UTC · Source

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) Apr 22, 2025

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

lucee_admin_imgprocess_file_write

metasploit · Created Unknown

Metasploit module for CVE-2021-21307

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit