Description
In Expression Engine before 6.0.3, addonIcon in Addons/file/mod.file.php relies on the untrusted input value of input->get('file') instead of the fixed file names of icon.png and icon.svg.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-19912 | In Expression Engine before 6.0.3, addonIcon in Addons/file/mod.file.php relies on the untrusted input value of input->get('file') instead of the fixed file names of icon.png and icon.svg. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T23:42:20.282Z
Reserved: 2021-05-19T00:00:00.000Z
Link: CVE-2021-33199
No data.
Status : Modified
Published: 2021-08-12T21:15:07.500
Modified: 2024-11-21T06:08:30.163
Link: CVE-2021-33199
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD