← Back to CVE List

CVE-2021-28132

Published: 2021-03-11T07:15Z
Last Modified: 2024-11-21T05:59Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
LUCY Security Awareness Software through 4.7.x allows unauthenticated remote code execution because the Migration Tool (in the Support section) allows upload of .php files within a system.tar.gz file. The .php file becomes accessible with a public/system/static URI. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt