Описание
Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creation functions (such as the Mkdir() function) gives universal access (0777) to created folders by default. Excessive permissions can be granted when creating a directory with permissions greater than 0755 or when the permissions argument is not specified.
Ссылки
- Release Notes
- Release Notes
- Release NotesVendor Advisory
- Release Notes
- Release Notes
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 8.5.13 (исключая)Версия от 9.0 (включая) до 9.2.2 (исключая)
Одно из
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 72%
0.00729
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-276
CWE-276
Связанные уязвимости
github
около 2 лет назад
Concrete CMS allows unauthorized access because directories can be created with insecure permissions
EPSS
Процентиль: 72%
0.00729
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-276
CWE-276