CVE-2021-28132

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
11/03/2021
Last modified:
22/03/2021

Description

LUCY Security Awareness Software through 4.7.x allows unauthenticated remote code execution because the Migration Tool (in the Support section) allows upload of .php files within a system.tar.gz file. The .php file becomes accessible with a public/system/static URI.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lucysecurity:security_awareness:*:*:*:*:*:*:*:* 4.7.8 (including)


References to Advisories, Solutions, and Tools