Unrated severityNVD Advisory· Published Mar 15, 2021· Updated Aug 3, 2024
CVE-2021-27230
CVE-2021-27230
Description
ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage Translate::save() to write to an _lang.php file under the system/user/language directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- ExpressionEngine/ExpressionEnginedescription
- Range: <5.4.2 || >=6.0.0, <6.0.3
Patches
Vulnerability mechanics
References
5- karmainsecurity.com/KIS-2021-03mitrex_refsource_MISC
- packetstormsecurity.com/files/161805/ExpressionEngine-6.0.2-PHP-Code-Injection.htmlmitrex_refsource_MISC
- seclists.org/fulldisclosure/2021/Mar/32mitrex_refsource_MISC
- expressionengine.com/featuresmitrex_refsource_MISC
- hackerone.com/reports/1093444mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.