CVE-2016-5661

NONE EPSS 83.2%
Published Jul 15, 20169y ago · Modified Jun 17, 20262w ago
Find Similar
Published Jul 15, 2016 9y ago
Last Modified Jun 17, 2026 2w ago

Description

Accela Civic Platform Citizen Access portal relies on the client to restrict file types for uploads, which allows remote authenticated users to execute arbitrary code via modified _EventArgument and filename parameters.

Threat Intelligence

EPSS Exploit Probability
83.2% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-284

Affected Products 1

VendorProductVersionRange
accelacivic_platform_citizen_access_portal*any

References 3

  • kb.cert.org http://www.kb.cert.org/vuls/id/665280
    Third Party AdvisoryUS Government Resource
  • kb.cert.org http://www.kb.cert.org/vuls/id/JLAD-ABMPVA
    Third Party AdvisoryUS Government Resource
  • securityfocus.com http://www.securityfocus.com/bid/91765

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.