CVE-2021-40108
- EPSS 0.5%
- Veröffentlicht 27.09.2021 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:23:34
An issue was discovered in Concrete CMS through 8.5.5. The Calendar is vulnerable to CSRF. ccm_token is not verified on the ccm/calendar/dialogs/event/add/save endpoint.
CVE-2021-40109
- EPSS 0.54%
- Veröffentlicht 27.09.2021 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:23:35
A SSRF issue was discovered in Concrete CMS through 8.5.5. Users can access forbidden files on their local network. A user with permissions to upload files from external sites can upload a URL that redirects to an internal resource of any file type. ...
CVE-2021-40098
- EPSS 1.63%
- Veröffentlicht 27.09.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:23:33
An issue was discovered in Concrete CMS through 8.5.5. Path Traversal leading to RCE via external form by adding a regular expression.
CVE-2021-40103
- EPSS 1.48%
- Veröffentlicht 27.09.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:23:34
An issue was discovered in Concrete CMS through 8.5.5. Path Traversal can lead to Arbitrary File Reading and SSRF.
CVE-2021-40104
- EPSS 1.38%
- Veröffentlicht 27.09.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:23:34
An issue was discovered in Concrete CMS through 8.5.5. There is an SVG sanitizer bypass.
CVE-2021-40105
- EPSS 0.65%
- Veröffentlicht 27.09.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:23:34
An issue was discovered in Concrete CMS through 8.5.5. There is XSS via Markdown Comments.
CVE-2021-40106
- EPSS 0.65%
- Veröffentlicht 27.09.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:23:34
An issue was discovered in Concrete CMS through 8.5.5. There is unauthenticated stored XSS in blog comments via the website field.
CVE-2021-40097
- EPSS 2.51%
- Veröffentlicht 27.09.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:23:33
An issue was discovered in Concrete CMS through 8.5.5. Authenticated path traversal leads to to remote code execution via uploaded PHP code, related to the bFilename parameter.
CVE-2021-40099
- EPSS 2.08%
- Veröffentlicht 24.09.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:23:33
An issue was discovered in Concrete CMS through 8.5.5. Fetching the update json scheme over HTTP leads to remote code execution.
CVE-2021-40100
- EPSS 0.52%
- Veröffentlicht 24.09.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:23:33
An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversation Editor is set to Rich Text.