CVE-2021-22951: High severity ConcreteCMS Concrete CMS vulnerability
Unauthorized individuals could view password protected files using viewinline in Concrete CMS (previously concrete 5) prior to version 8.5.7. Concrete CMS now checks to see if a file has a password in viewinline and, if it does, the file is not rendered.For version 8.5.6, the following mitigations were put in place a. restricting file types for viewinline to images only b. putting a warning in the file manager to advise users.Credit for discovery: "Solar Security Research Team"Concrete CMS security team CVSS scoring is 5.3: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NThis fix is also in Concrete version 9.0.0
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-22951.
What is the severity of CVE-2021-22951?
The severity of CVE-2021-22951 is high with a CVSS score of 7.5.
How can unauthorized individuals view password protected files using view_inline in Concrete CMS?
Unauthorized individuals can view password protected files using view_inline in Concrete CMS prior to version 8.5.7.
What has Concrete CMS done to mitigate this vulnerability?
Concrete CMS now checks to see if a file has a password in view_inline and, if it does, the file is not rendered.
How can I fix CVE-2021-22951 in Concrete CMS?
To fix CVE-2021-22951, it is recommended to update your Concrete CMS installation to version 8.5.7 or later.