VDB
Sign up
MEDIUM4.3

GHSA-3rxx-8f33-7p6p

Concrete CMS Cross Site Request Forgery (CSRF) vulnerability

Quick fix

GHSA-3rxx-8f33-7p6p — concrete5/concrete5: upgrade to the fixed version with the command below.

composer require concrete5/concrete5:^8.5.14

Details

Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/delete/submit. An attacker can force an admin to delete events on the site because the event ID is numeric and sequential.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/concrete5/concrete5
Introduced in: 0Fixed in: 8.5.14
Fixcomposer require concrete5/concrete5:^8.5.14
Packagist/concrete5/concrete5
Introduced in: 9.0.0Fixed in: 9.2.3
Fixcomposer require concrete5/concrete5:^9.2.3

References