Back to Database
Status published
High
CVE-2021-27990
Appspace 6.2.4 is vulnerable to a broken authentication mechanism where...
Vulnerability Description
Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed with layouts, menus and functionalities.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-27990
Credits & Attribution
No credits recorded in the NVD database.
More from appspace
View All →CVE-2021-27989
Appspace 6.2.4 is vulnerable to stored cross-site scripting (XSS) in...
Medium
5.4
CVE-2021-27704
Appspace 6.2.4 is affected by Incorrect Access Control via the...
Unknown
0
CVE-2021-27670
Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter....
Critical
9.8
CVE-2021-27564
A stored XSS issue exists in Appspace 6.2.4. After a...
Medium
5.4
CVE-2020-5393
In Appspace On-Prem through 7.1.3, an adversary can steal a...
Medium
6.1
Affected Vendor
appspace
View all reports →Affected Software
appspace
Vulnerable Versions:
6.2.4
Timeline
Official Publish:
April 14th, 2021
Last Modified:
July 9th, 2026
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.