CVE-2021-27230

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
15/03/2021
Last modified:
12/07/2022

Description

ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage Translate::save() to write to an _lang.php file under the system/user/language directory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:expressionengine:expressionengine:*:*:*:*:*:*:*:* 5.4.2 (excluding)
cpe:2.3:a:expressionengine:expressionengine:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.3 (excluding)