CVE-2021-40102
EUVD-2021-2729124.09.2021, 15:15
An issue was discovered in Concrete CMS through 8.5.5. Arbitrary File deletion can occur via PHAR deserialization in is_dir (PHP Object Injection associated with the __wakeup magic method).Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| concretecms | concrete_cms | 𝑥 ≤ 8.5.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration