An issue was discovered in Concrete CMS through 8.5.5. Arbitrary File deletion can occur via PHAR deserialization in is_dir (PHP Object Injection associated with the __wakeup magic method).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-09-24T14:55:42

Updated: 2024-08-04T02:27:31.463Z

Reserved: 2021-08-25T00:00:00

Link: CVE-2021-40102

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-09-24T15:15:08.730

Modified: 2021-09-30T17:19:45.320

Link: CVE-2021-40102

cve-icon Redhat

No data.