VDB
Sign up
LOW

GHSA-6mxw-2vhf-42g5

Concrete CMS vulnerable to Cross-Site Request Forgery (CSRF)

Quick fix

GHSA-6mxw-2vhf-42g5 — concrete5/concrete5: upgrade to the fixed version with the command below.

composer require concrete5/concrete5:^9.4.8

Details

Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configuration via group_id parameter which can leads to a security bypass since changes are saved prior to checking the CSRF token. 

The Concrete CMS security team thanks z3rco for reporting

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/concrete5/concrete5
Introduced in: 0Fixed in: 9.4.8
Fixcomposer require concrete5/concrete5:^9.4.8

References