First published: Thu Sep 23 2021(Updated: )
Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery: "Solar Security Research Team"
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Concrete5 | <8.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22950 is classified as a medium severity vulnerability due to its potential for CSRF attacks leading to unauthorized deletion of attachments.
To remediate CVE-2021-22950, you should upgrade Concrete CMS to version 8.5.6 or later.
CVE-2021-22950 affects all versions of Concrete CMS prior to 8.5.6.
The impact of CVE-2021-22950 is that it allows attackers to delete comment attachments without proper authorization.
CVE-2021-22950 was discovered by the Solar Security Research Team.