Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33082
HistoryNov 24, 2021 - 6:32 a.m.

Privilege Escalation

2021-11-2406:32:29
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.001 Low

EPSS

Percentile

42.8%

concrete5/concrete5 is vulnerable to privilege escalation. The vulnerability exists in ‘bulkupdate.php’ because the ‘view’ permissions granted users in that group can escalate to being an administrator using specially crafted curl.

0.001 Low

EPSS

Percentile

42.8%