Code Injection in concrete5 - CVE-2022-21829

 

Code Injection in concrete5 - CVE-2022-21829

Published: June 21, 2022


Vulnerability identifier: #VU64525
CSH Severity: Low
CVSS v4: 5.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H]
CVE-ID: CVE-2022-21829
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to the affected application can download zip files over HTTP. A remote administrator can execute arbitrary code from those zip files on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

concrete5

How to mitigate CVE-2022-21829

Install updates from vendor's website.

concrete5 - update to 8.5.8

External References

Related Security Bulletins