CVE-2021-22953: CSRF
Published Sep 23, 2021
·Updated
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security Research Team"
Affected Software
1 affected component
ConcreteCMS Concrete CMS<=8.5.5
Event History
Sep 23, 2021
CVE Published
via MITRE·12:42 PM
Data Sourced
via MITRE·12:42 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22953?
CVE-2021-22953 has a medium severity rating due to its potential impact on user experience and resource usage.
2
How do I fix CVE-2021-22953?
To fix CVE-2021-22953, upgrade to Concrete CMS version 8.5.6 or higher, which addresses the CSRF vulnerability.
3
What is the impact of CVE-2021-22953?
The impact of CVE-2021-22953 includes the potential for unauthorized topic cloning, leading to UI issues and excessive disk space usage.
4
Who discovered CVE-2021-22953?
CVE-2021-22953 was discovered by the Solar Security Research Team.
5
Which versions of Concrete CMS are affected by CVE-2021-22953?
Concrete CMS versions 8.5.5 and below are affected by CVE-2021-22953.