CVE-2021-40098: Path Traversal
Published Sep 27, 2021
·Updated
An issue was discovered in Concrete CMS through 8.5.5. Path Traversal leading to RCE via external form by adding a regular expression.
Affected Software
1 affected component
ConcreteCMS Concrete CMS<=8.5.5
Event History
Sep 27, 2021
CVE Published
via MITRE·11:08 AM
Data Sourced
via MITRE·11:08 AM
Description
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-40098?
CVE-2021-40098 is a vulnerability in Concrete CMS through version 8.5.5 that allows path traversal leading to remote code execution (RCE) via an external form.
2
How severe is CVE-2021-40098?
CVE-2021-40098 has a severity rating of 9.8, which is considered critical.
3
Which versions of Concrete CMS are affected by CVE-2021-40098?
Concrete CMS versions up to and including 8.5.5 are affected by CVE-2021-40098.
4
How can I fix CVE-2021-40098?
To fix CVE-2021-40098, it is recommended to update Concrete CMS to a version beyond 8.5.5.
5
Where can I find more information about CVE-2021-40098?
You can find more information about CVE-2021-40098 in the release notes of Concrete CMS version 8.5.6 and the associated HackerOne report.