CVE-2021-40097
EUVD-2021-2728627.09.2021, 12:15
An issue was discovered in Concrete CMS through 8.5.5. Authenticated path traversal leads to to remote code execution via uploaded PHP code, related to the bFilename parameter.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| concretecms | concrete_cms | 𝑥 ≤ 8.5.5 |
𝑥
= Vulnerable software versions