Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS13OGZwLTNnd3EtZ3hwd84AAv2t

Concrete CMS vulnerable to Cross-site Request Forgery

Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete who use the "out of the box" core OAuth.

Permalink: https://github.com/advisories/GHSA-w8fp-3gwq-gxpw
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13OGZwLTNnd3EtZ3hwd84AAv2t
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: 10 months ago
Updated: 8 months ago


CVSS Score: 8.8
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Identifiers: GHSA-w8fp-3gwq-gxpw, CVE-2022-43693
References:

Affected Packages

packagist:concrete5/concrete5
Versions: >= 9.0.0RC1, < 9.1.3, < 8.5.10
Fixed in: 9.1.3, 8.5.10