Lucee Protection Mechanism Failure Vulnerability Allowing Code Execution and Resource Access

Vulnerability

A vulnerability exists in Lucee versions prior to 5.4.7.3 LTS and in the 6.x series prior to 6.1.1.118. When an attacker can upload files to the server, this vulnerability allows for a failure in the protection mechanism, potentially enabling the execution of blocked code and access to protected resources.

Impact

Exploitation of this vulnerability could lead to unauthorized code execution on the server and access to restricted resources.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.