ZeroHour

CVE-2021-40097

CVSS 3.1
8.8 high
EPSS
3%p84
Published
()
Modified
Description

An issue was discovered in Concrete CMS through 8.5.5. Authenticated path traversal leads to to remote code execution via uploaded PHP code, related to the bFilename parameter.

Vendors
concretecms
Products
concrete cms
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.