HIGH
GHSA-gr23-g276-xc73
Cross Site Request Forgery in concrete5/concrete5
Quick fix
GHSA-gr23-g276-xc73 — concrete5/concrete5: upgrade to the fixed version with the command below.
composer require concrete5/concrete5:^9.0.0Details
A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other users.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/concrete5/concrete5
Introduced in:
0Fixed in: 9.0.0Fix
composer require concrete5/concrete5:^9.0.0