Описание
Concrete CMS vulnerable to XML External Entity
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XXE based DNS requests leading to IP disclosure.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2022-43689
- https://documentation.concretecms.org/developers/introduction/version-history/8510-release-notes
- https://documentation.concretecms.org/developers/introduction/version-history/913-release-notes
- https://github.com/concretecms/concretecms/releases/8.5.10
- https://github.com/concretecms/concretecms/releases/9.1.3
- https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2022-10-31
Пакеты
Наименование
concrete5/concrete5
composer
Затронутые версииВерсия исправления
< 8.5.10
8.5.10
Наименование
concrete5/concrete5
composer
Затронутые версииВерсия исправления
>= 9.0.0, < 9.1.2
9.1.2
Связанные уязвимости
CVSS3: 5.3
nvd
около 3 лет назад
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XXE based DNS requests leading to IP disclosure.