CVE-2021-27230
15.03.2021, 23:15
ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage Translate::save() to write to an _lang.php file under the system/user/language directory.
Vendor | Product | Version |
---|---|---|
expressionengine | expressionengine | 𝑥 < 5.4.2 |
expressionengine | expressionengine | 6.0.0 ≤ 𝑥 < 6.0.3 |
𝑥
= Vulnerable software versions
References