First published: Thu Sep 23 2021(Updated: )
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security Research Team"
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Concrete5 | <=8.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22953 has a medium severity rating due to its potential impact on user experience and resource usage.
To fix CVE-2021-22953, upgrade to Concrete CMS version 8.5.6 or higher, which addresses the CSRF vulnerability.
The impact of CVE-2021-22953 includes the potential for unauthorized topic cloning, leading to UI issues and excessive disk space usage.
CVE-2021-22953 was discovered by the Solar Security Research Team.
Concrete CMS versions 8.5.5 and below are affected by CVE-2021-22953.