Loading
An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted environment variables into vulnerable CGI scripts.
Use CWE-434, Embedthis vendor hub and Goahead product page to widen CVE-2021-42342 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-41615, CVE-2021-43298 and CVE-2019-5096 for nearby disclosures in the same product family.