- Concrete5 version 5.7.3.1 is vulnerable to remote code execution (RCE) via a vulnerability in its sendmail functionality that allows arbitrary command execution when sending registration notification emails. An authenticated administrator can be tricked via CSRF into configuring notification emails with a specially crafted address that executes code. This allows an attacker to execute code by registering a new user account. The vulnerability is fixed in version 5.7.4.