6.5

CVE-2017-8082

Exploit
concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the /tools/required/files/importers/imageeditor?fID=1&imgData= URI. This results in a site-wide denial of service making the site not accessible to any users or any administrators.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ConcretecmsConcrete Cms Version8.1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.2% 0.641
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

http://zeroday.insecurity.zone/exploits/concrete5_csrf_dos.txt
Third Party Advisory
Exploit
https://drive.google.com/open?id=0B3vXUYdNMECWZTd3SFRnUjllWk0
Exploit
https://twitter.com/insecurity/status/856066923146215425
Third Party Advisory