Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x2fp-hj8c-mmxh

Опубликовано: 21 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.3
CVSS3: 5.3

Описание

Concrete CMS is vulnerable to authorization bypass in the Calendar Event Frontend Dialog

Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow cross-calendar data disclosure. A public calendar block can be used as a pivot point to access private calendar data.

Пакеты

Наименование

concrete5/concrete5

composer
Затронутые версииВерсия исправления

< 9.5.1

9.5.1

EPSS

Процентиль: 12%
0.00211
Низкий

6.3 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 5.3
nvd
2 месяца назад

Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow cross-calendar data disclosure. A public calendar block can be used as a pivot point to access private calendar data. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.

EPSS

Процентиль: 12%
0.00211
Низкий

6.3 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-639