CVE Vulnerabilities

CVE-2021-40099

Published: Sep 24, 2021 | Modified: Sep 30, 2021
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in Concrete CMS through 8.5.5. Fetching the update json scheme over HTTP leads to remote code execution.

Affected Software

Name Vendor Start Version End Version
Concrete_cms Concretecms * 8.5.5 (including)

References