VDB
Sign up
MEDIUM4.3

GHSA-qp42-5pj7-4ccm

Concrete CMS Cross Site Request Forgery (CSRF)

Quick fix

GHSA-qp42-5pj7-4ccm — concrete5/concrete5: upgrade to the fixed version with the command below.

composer require concrete5/concrete5:^9.2.3

Details

Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) via `/ccm/system/dialogs/logs/delete_all/submit`. An attacker can force an admin user to delete server report logs on a web application to which they are currently authenticated.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/concrete5/concrete5
Introduced in: 0Fixed in: 9.2.3
Fixcomposer require concrete5/concrete5:^9.2.3

References