Описание
Concrete CMS (previously concrete5) is vulnerable to possible auth bypass in the jobs section
Concrete CMS (previously concrete5) before 9.2 is vulnerable to possible Auth bypass in the jobs section.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-28473
- https://github.com/concretecms/concretecms/pull/11749
- https://concretecms.com
- https://github.com/concretecms/concretecms/releases/tag/8.5.13
- https://www.concretecms.org/about/project-news/security/2023-11-09-security-blog-about-updated-cves-and-new-release
- https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2023-04-20
Пакеты
Наименование
concrete5/concrete5
composer
Затронутые версииВерсия исправления
< 9.2.0
9.2.0
Связанные уязвимости
CVSS3: 3.3
nvd
почти 3 года назад
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to possible Auth bypass in the jobs section.