Vulnerability Description
LUCY Security Awareness Software through 4.7.x allows unauthenticated remote code execution because the Migration Tool (in the Support section) allows upload of .php files within a system.tar.gz file. The .php file becomes accessible with a public/system/static URI.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lucysecurity | Security Awareness | <= 4.7.8 |
Related Weaknesses (CWE)
References
- https://abuyv.com/cve/lucy-file-upload-RCEExploitThird Party Advisory
- https://abuyv.com/cve/lucy-file-upload-RCEExploitThird Party Advisory
FAQ
What is CVE-2021-28132?
CVE-2021-28132 is a vulnerability with a CVSS score of 9.8 (CRITICAL). LUCY Security Awareness Software through 4.7.x allows unauthenticated remote code execution because the Migration Tool (in the Support section) allows upload of .php files within a system.tar.gz file....
How severe is CVE-2021-28132?
CVE-2021-28132 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-28132?
Check the references section above for vendor advisories and patch information. Affected products include: Lucysecurity Security Awareness.