#VU64525 Code Injection in concrete5 - CVE-2022-21829
Published: June 21, 2022
concrete5
PortlandLabs
Description
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to the affected application can download zip files over HTTP. A remote administrator can execute arbitrary code from those zip files on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.