HIGH7.2
GHSA-hf9p-9r39-r2h3
Unrestricted Uploads in Concrete5
Quick fix
GHSA-hf9p-9r39-r2h3 — concrete5/concrete5: upgrade to the fixed version with the command below.
composer require concrete5/concrete5:^8.5.3Details
Concrete5 before 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/concrete5/concrete5
Introduced in:
0Fixed in: 8.5.3Fix
composer require concrete5/concrete5:^8.5.3References
- https://nvd.nist.gov/vuln/detail/CVE-2020-11476[ADVISORY]
- https://github.com/concrete5/concrete5/pull/8713[WEB]
- https://github.com/concretecms/concretecms/commit/d296f4ba4f6ad94b199c21c1b16f0d185adab343[WEB]
- https://github.com/concrete5/concrete5[PACKAGE]
- https://github.com/concrete5/concrete5/releases/tag/8.5.3[WEB]
- https://herolab.usd.de/security-advisories/usd-2020-0041[WEB]