Lucene search

K
cvelistMitreCVELIST:CVE-2021-40109
HistorySep 27, 2021 - 12:04 p.m.

CVE-2021-40109

2021-09-2712:04:54
mitre
www.cve.org

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.7%

A SSRF issue was discovered in Concrete CMS through 8.5.5. Users can access forbidden files on their local network. A user with permissions to upload files from external sites can upload a URL that redirects to an internal resource of any file type. The redirect is followed and loads the contents of the file from the redirected-to server. Files of disallowed types can be uploaded.

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.7%

Related for CVELIST:CVE-2021-40109