VDB
KO
LOW

GHSA-gjwq-9v8p-47w7

Concrete CMS's RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation

Details

In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation enabling redirect-to-internal bypasses.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist / concrete5/concrete5
Introduced in: 0 Fixed in: 9.5.1
Fix composer require concrete5/concrete5:^9.5.1

References