ZeroHour

CVE-2021-40099

CVSS 3.1
7.2 high
EPSS
2%p80
Published
()
Modified
Description

An issue was discovered in Concrete CMS through 8.5.5. Fetching the update json scheme over HTTP leads to remote code execution.

Vendors
concretecms
Products
concrete cms
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.