First published: Thu Sep 23 2021(Updated: )
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security CMS Research Team"
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Concrete5 | <=8.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-22949 is considered low, primarily affecting user experience and disk space management.
CVE-2021-22949 affects Concrete CMS versions 8.5.5 and below.
To fix CVE-2021-22949, upgrade to Concrete CMS version 8.5.6 or later.
CVE-2021-22949 is a Cross-Site Request Forgery (CSRF) vulnerability.
The potential impacts of CVE-2021-22949 include file duplication, user interface issues, and excessive disk space usage.