First published: Mon Sep 27 2021(Updated: )
An issue was discovered in Concrete CMS through 8.5.5. Path Traversal leading to RCE via external form by adding a regular expression.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Concretecms Concrete Cms | <=8.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40098 is a vulnerability in Concrete CMS through version 8.5.5 that allows path traversal leading to remote code execution (RCE) via an external form.
CVE-2021-40098 has a severity rating of 9.8, which is considered critical.
Concrete CMS versions up to and including 8.5.5 are affected by CVE-2021-40098.
To fix CVE-2021-40098, it is recommended to update Concrete CMS to a version beyond 8.5.5.
You can find more information about CVE-2021-40098 in the release notes of Concrete CMS version 8.5.6 and the associated HackerOne report.