Описание
Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) via /ccm/system/dialogs/logs/delete_all/submit. An attacker can force an admin user to delete server report logs on a web application to which they are currently authenticated.
Ссылки
- Release Notes
- PatchVendor Advisory
- Release Notes
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 9.0 (включая) до 9.2.3 (исключая)
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 49%
0.00256
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-352
Связанные уязвимости
EPSS
Процентиль: 49%
0.00256
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-352