CVE-2021-22949: CSRF
Published Sep 23, 2021
·Updated
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security CMS Research Team"
Affected Software
1 affected component
ConcreteCMS Concrete CMS<=8.5.5
Event History
Sep 23, 2021
CVE Published
via MITRE·12:40 PM
Data Sourced
via MITRE·12:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22949?
The severity of CVE-2021-22949 is considered low, primarily affecting user experience and disk space management.
2
Which versions of Concrete CMS are affected by CVE-2021-22949?
CVE-2021-22949 affects Concrete CMS versions 8.5.5 and below.
3
How do I fix CVE-2021-22949?
To fix CVE-2021-22949, upgrade to Concrete CMS version 8.5.6 or later.
4
What type of vulnerability is CVE-2021-22949?
CVE-2021-22949 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
What are the potential impacts of CVE-2021-22949?
The potential impacts of CVE-2021-22949 include file duplication, user interface issues, and excessive disk space usage.