CVE-2021-33199

CRITICAL

Expression Engine <6.0.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

In Expression Engine before 6.0.3, addonIcon in Addons/file/mod.file.php relies on the untrusted input value of input->get('file') instead of the fixed file names of icon.png and icon.svg.

Scores

CVSS v3 9.8
EPSS 0.0136
EPSS Percentile 68.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (1)
expressionengine/expressionengine < 6.0.3
Published Aug 12, 2021
Tracked Since Feb 18, 2026