8.8

CVE-2022-43693

Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete who use the "out of the box" core OAuth.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ConcretecmsConcrete Cms Version < 8.5.10
ConcretecmsConcrete Cms Version >= 9.0.0 <= 9.1.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.44% 0.35
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

https://documentation.concretecms.org/developers/introduction/version-history/8510-release-notes
Vendor Advisory
Release Notes
https://documentation.concretecms.org/developers/introduction/version-history/913-release-notes
Vendor Advisory
Release Notes
https://github.com/concretecms/concretecms/releases/8.5.10
Patch
Third Party Advisory
Release Notes
https://github.com/concretecms/concretecms/releases/9.1.3
Patch
Third Party Advisory
Release Notes
https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2022-10-31
Vendor Advisory