LOW
GHSA-xjg6-5v39-v7fc
Concrete CMS is vulnerable to CSRF via Backend\File::approveVersion
Details
Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents permission is CSRF'd into publishing an attacker-chosen previously-uploaded version (downgrade to an older version of a file, or activation of a co-editor's unpublished version). Thanks Winston Crooker for reporting.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist / concrete5/concrete5
Introduced in:
0 Fixed in: 9.5.1 Fix
composer require concrete5/concrete5:^9.5.1