Concretecms

Concrete Cms

119 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 9.14%
  • Veröffentlicht 30.11.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:23:33

An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.

  • EPSS 0.31%
  • Veröffentlicht 19.11.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 05:51:00

Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.7. Concrete CMS now checks to see if a file has a password in view_inline and, if it does, the file is not ren...

  • EPSS 0.27%
  • Veröffentlicht 19.11.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 05:51:02

Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted "view" permissions on the bulkupdate page, then users in that group can escalate to being an administrator with a specially crafted...

  • EPSS 0.75%
  • Veröffentlicht 19.11.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 05:51:02

In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to a Conversation.To remediate this, a check was added to verify a user has permissions to view files before atta...

Exploit
  • EPSS 2.66%
  • Veröffentlicht 19.11.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 05:51:02

A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Concrete CMS (concrete5) versions 8.5.6 and below.The external file upload feature stages files in the public directory even if they...

  • EPSS 0.27%
  • Veröffentlicht 19.11.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 05:51:02

Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch cloud IAAS (ex AWS) IAM keys.To fix this Concrete CMS no longer allows downloads from the local networ...

  • EPSS 0.39%
  • Veröffentlicht 19.11.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 05:51:02

Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable toa. SSRF attacks on the private LAN servers by reading files from the local LAN. An attacker can pivot in the p...

  • EPSS 0.4%
  • Veröffentlicht 07.10.2021 14:15:08
  • Zuletzt bearbeitet 21.11.2024 05:51:01

A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the limitations in place for localhost allowing interaction with local services. Impact can vary depending on serv...

  • EPSS 0.13%
  • Veröffentlicht 27.09.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:23:34

An issue was discovered in Concrete CMS through 8.5.5. The Calendar is vulnerable to CSRF. ccm_token is not verified on the ccm/calendar/dialogs/event/add/save endpoint.

  • EPSS 0.1%
  • Veröffentlicht 27.09.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:23:35

A SSRF issue was discovered in Concrete CMS through 8.5.5. Users can access forbidden files on their local network. A user with permissions to upload files from external sites can upload a URL that redirects to an internal resource of any file type. ...