Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33097
HistoryNov 25, 2021 - 1:10 p.m.

Remote Code Execution (RCE)

2021-11-2513:10:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.01 Low

EPSS

Percentile

83.5%

concrete5/concrete5 is vulnerable to remote code execution. An attacker is able to inject and execute malicious code via external file upload feature because, the library stages files in the public directory even when they have disallowed file extensions.

0.01 Low

EPSS

Percentile

83.5%