Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8c7c-h7px-267g

Опубликовано: 22 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.3

Описание

Concrete CMS is vulnerable to IDOR in surveys

Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in such a way that both public and private surveys are present on the site. An unauthenticated attacker can vote in the restricted survey by submitting the restricted optionID through the public survey’s endpoint.

Пакеты

Наименование

concrete5/concrete5

composer
Затронутые версииВерсия исправления

< 9.5.1

9.5.1

EPSS

Процентиль: 9%
0.00194
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-565

Связанные уязвимости

CVSS3: 5.3
nvd
2 месяца назад

Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in such a way that both public and private surveys are present on the site. An unauthenticated attacker can vote in the restricted survey by submitting the restricted optionID through the public survey’s endpoint. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks  Zer0daySec https://github.com/Zee99y  for reporting

EPSS

Процентиль: 9%
0.00194
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-565