Опубликовано: 21 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.3
CVSS3: 5.3
Описание
Concrete CMS is vulnerable to authorization bypass in the Calendar Block
Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since action_get_events does not check canView on the calendar which results in restricted event details being disclosed.
Пакеты
Наименование
concrete5/concrete5
composer
Затронутые версииВерсия исправления
< 9.5.1
9.5.1
Связанные уязвимости
CVSS3: 5.3
nvd
2 месяца назад
Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since action_get_events does not check canView on the calendar which results in restricted event details being disclosed. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks lalalala5678 for reporting.