CVE-2021-40097: Path Traversal
Published Sep 27, 2021
·Updated
An issue was discovered in Concrete CMS through 8.5.5. Authenticated path traversal leads to to remote code execution via uploaded PHP code, related to the bFilename parameter.
Affected Software
1 affected component
ConcreteCMS Concrete CMS<=8.5.5
Event History
Sep 27, 2021
CVE Published
via MITRE·11:06 AM
Data Sourced
via MITRE·11:06 AM
Description
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-40097?
CVE-2021-40097 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2021-40097?
To address CVE-2021-40097, upgrade Concrete CMS to version 8.5.6 or later.
3
What does CVE-2021-40097 exploit?
CVE-2021-40097 exploits an authenticated path traversal vulnerability that allows for the execution of uploaded PHP code.
4
Who is affected by CVE-2021-40097?
CVE-2021-40097 affects all versions of Concrete CMS up to 8.5.5.
5
Is there a workaround for CVE-2021-40097?
Currently, the best mitigation for CVE-2021-40097 is to apply the available security update.