Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31447
HistoryAug 02, 2021 - 7:37 a.m.

Arbitrary Code Execution

2021-08-0207:37:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.013 Low

EPSS

Percentile

86.1%

concrete5/concrete5 is vulnerable to arbitrary code execution. An attacker is able to submit malicious data to the function Logging::update_logging() in controllers/single_page/dashboard/system/environment/logging.php via logFile request parameter, to execute arbitrary code via unsafe deserialization.

0.013 Low

EPSS

Percentile

86.1%