CVE-2024-55354

HIGH

Lucee <5.4.7.3 LTS & 6 <6.1.1.118 - Code Injection

Title source: llm
STIX 2.1

Description

Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can place files on the server, is vulnerable to a protection mechanism failure that can let an attacker run code that would be expected to be blocked and access resources that would be expected to be protected.

Scores

CVSS v3 8.8
EPSS 0.0008
EPSS Percentile 22.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-807
Status published
Products (2)
Lucee/Lucee Server < 5.4.7.3 LTS
Lucee/Lucee Server 6 - 6.1.1.118
Published Apr 08, 2025
Tracked Since Feb 18, 2026