LOW
GHSA-gjwq-9v8p-47w7
Concrete CMS's RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation
Details
In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation enabling redirect-to-internal bypasses.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist / concrete5/concrete5
Introduced in:
0 Fixed in: 9.5.1 Fix
composer require concrete5/concrete5:^9.5.1