PT-2021-22811 · Unknown · Concrete Cms

Reset

·

Published

2021-09-24

·

Updated

2021-09-30

·

CVE-2021-40102

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Concrete CMS versions through 8.5.5
Description An issue in Concrete CMS allows for arbitrary file deletion via PHAR deserialization in the is dir function, which is associated with PHP Object Injection and the wakeup magic method.
Recommendations For versions through 8.5.5, consider disabling the is dir function or restricting its use until a patch is available to prevent PHP Object Injection associated with the wakeup magic method. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-40102

Affected Products

Concrete Cms