LOW
GHSA-6mxw-2vhf-42g5
Concrete CMS vulnerable to Cross-Site Request Forgery (CSRF)
Quick fix
GHSA-6mxw-2vhf-42g5 — concrete5/concrete5: upgrade to the fixed version with the command below.
composer require concrete5/concrete5:^9.4.8Details
Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configuration via group_id parameter which can leads to a security bypass since changes are saved prior to checking the CSRF token.
The Concrete CMS security team thanks z3rco for reporting
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/concrete5/concrete5
Introduced in:
0Fixed in: 9.4.8Fix
composer require concrete5/concrete5:^9.4.8