Vulnerabilities > Lucysecurity

DATE CVE VULNERABILITY TITLE RISK
2021-03-11 CVE-2021-28132 OS Command Injection vulnerability in Lucysecurity Security Awareness
LUCY Security Awareness Software through 4.7.x allows unauthenticated remote code execution because the Migration Tool (in the Support section) allows upload of .php files within a system.tar.gz file.
network
low complexity
lucysecurity CWE-78
critical
9.8