Логотип exploitDog
bind:CVE-2022-21829
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-21829

Количество 2

Количество 2

nvd логотип

CVE-2022-21829

больше 3 лет назад

Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which could lead to an RCE. Fixed by enforcing ‘concrete_secure’ instead of ‘concrete’. Concrete now only makes requests over https even a request comes in via http. Concrete CMS security team ranked this 8 with CVSS v3.1 vector: AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Credit goes to Anna for reporting HackerOne 1482520.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-6xc4-7fmm-65q2

больше 3 лет назад

Code injection in concrete CMS

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-21829

Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which could lead to an RCE. Fixed by enforcing ‘concrete_secure’ instead of ‘concrete’. Concrete now only makes requests over https even a request comes in via http. Concrete CMS security team ranked this 8 with CVSS v3.1 vector: AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Credit goes to Anna for reporting HackerOne 1482520.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-6xc4-7fmm-65q2

Code injection in concrete CMS

CVSS3: 8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу