High severity7.2NVD Advisory· Published Jul 28, 2020· Updated Jun 17, 2026
CVE-2020-11476
CVE-2020-11476
Description
Concrete5 before 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
concrete5/concrete5Packagist | < 8.5.3 | 8.5.3 |
Affected products
3- Concrete5/Concrete5description
Patches
Vulnerability mechanics
References
8- github.com/concrete5/concrete5/pull/8713nvdPatchThird Party AdvisoryWEB
- herolab.usd.de/security-advisories/usd-2020-0041/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-hf9p-9r39-r2h3ghsaADVISORY
- github.com/concrete5/concrete5/releases/tag/8.5.3nvdRelease NotesThird Party AdvisoryWEB
- herolab.usd.de/security-advisories/nvdThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2020-11476ghsaADVISORY
- github.com/concretecms/concretecms/commit/d296f4ba4f6ad94b199c21c1b16f0d185adab343ghsaWEB
- herolab.usd.de/security-advisories/usd-2020-0041ghsaWEB
News mentions
0No linked articles in our index yet.