High severity8.8NVD Advisory· Published Mar 15, 2021· Updated Jun 17, 2026
CVE-2021-27230
CVE-2021-27230
Description
ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage Translate::save() to write to an _lang.php file under the system/user/language directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:expressionengine:expressionengine:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:expressionengine:expressionengine:*:*:*:*:*:*:*:*range: <5.4.2
- (no CPE)range: <5.4.2, <6.0.3
- ExpressionEngine/ExpressionEnginedescription
Patches
Vulnerability mechanics
References
5- karmainsecurity.com/KIS-2021-03nvdExploitThird Party Advisory
- packetstormsecurity.com/files/161805/ExpressionEngine-6.0.2-PHP-Code-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2021/Mar/32nvdMailing ListThird Party Advisory
- expressionengine.com/featuresnvdVendor Advisory
- hackerone.com/reports/1093444nvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.