MEDIUM4.3
GHSA-3rxx-8f33-7p6p
Concrete CMS Cross Site Request Forgery (CSRF) vulnerability
Quick fix
GHSA-3rxx-8f33-7p6p — concrete5/concrete5: upgrade to the fixed version with the command below.
composer require concrete5/concrete5:^8.5.14Details
Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/delete/submit. An attacker can force an admin to delete events on the site because the event ID is numeric and sequential.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/concrete5/concrete5
Introduced in:
0Fixed in: 8.5.14Fix
composer require concrete5/concrete5:^8.5.14Packagist/concrete5/concrete5
Introduced in:
9.0.0Fixed in: 9.2.3Fix
composer require concrete5/concrete5:^9.2.3References
- https://nvd.nist.gov/vuln/detail/CVE-2023-48653[ADVISORY]
- https://github.com/concretecms/concretecms/commit/077755e6bbbc1c67b7508add9e3d207e8d8909a0[WEB]
- https://github.com/concretecms/concretecms/commit/5b93470bcccf271810d3a0b190368ce6a9d6c84b[WEB]
- https://documentation.concretecms.org/developers/introduction/version-history/923-release-notes[WEB]
- https://github.com/concretecms/concretecms[PACKAGE]
- https://www.concretecms.org/about/project-news/security/2023-12-05-concrete-cms-new-cves-and-cve-updates[WEB]