Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-99286
HistorySep 26, 2021 - 12:00 a.m.

Concrete CMS arbitrary file deletion vulnerability

2021-09-2600:00:00
China National Vulnerability Database
www.cnvd.org.cn
9

0.003 Low

EPSS

Percentile

68.1%

Concrete CMS is an open source content management system for teams.Concrete CMS 8.5.5 and earlier versions are vulnerable to arbitrary file deletion. An attacker could exploit the vulnerability to delete arbitrary files via PHAR deserialization in is_dir.

CPENameOperatorVersion
portland labs concrete cmsle8.5.5

0.003 Low

EPSS

Percentile

68.1%

Related for CNVD-2021-99286