Fiche vulnérabilité
CVE-2021-28132 : faille critique lucysecurity security awareness (CVSS 9.8)
Description
LUCY Security Awareness Software through 4.7.x allows unauthenticated remote code execution because the Migration Tool (in the Support section) allows upload of .php files within a system.tar.gz file. The .php file becomes accessible with a public/system/static URI.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 11 mars 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- lucysecurity security awareness