Описание
Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete who use the "out of the box" core OAuth.
Ссылки
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- PatchRelease NotesThird Party Advisory
- PatchRelease NotesThird Party Advisory
- Vendor Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- PatchRelease NotesThird Party Advisory
- PatchRelease NotesThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 8.5.10 (исключая)Версия от 9.0.0 (включая) до 9.1.2 (включая)
Одно из
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 62%
0.00428
Низкий
8.8 High
CVSS3
Дефекты
CWE-352
CWE-352
Связанные уязвимости
CVSS3: 8.8
github
около 3 лет назад
Concrete CMS vulnerable to Cross-site Request Forgery
EPSS
Процентиль: 62%
0.00428
Низкий
8.8 High
CVSS3
Дефекты
CWE-352
CWE-352