Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9jj7-ch3r-h65g

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Concrete CMS through 8.5.5. The Calendar is vulnerable to CSRF. ccm_token is not verified on the ccm/calendar/dialogs/event/add/save endpoint.

An issue was discovered in Concrete CMS through 8.5.5. The Calendar is vulnerable to CSRF. ccm_token is not verified on the ccm/calendar/dialogs/event/add/save endpoint.

EPSS

Процентиль: 32%
0.00125
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

An issue was discovered in Concrete CMS through 8.5.5. The Calendar is vulnerable to CSRF. ccm_token is not verified on the ccm/calendar/dialogs/event/add/save endpoint.

EPSS

Процентиль: 32%
0.00125
Низкий

Дефекты

CWE-352