First published: Wed Feb 09 2022(Updated: )
A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other users.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Concretecms Concrete Cms | <9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22954 is a cross-site request forgery vulnerability in Concrete CMS <v9.
CVE-2021-22954 allows an attacker to make requests on behalf of other users in Concrete CMS <v9.
CVE-2021-22954 has a severity rating of 8.8 (high).
To fix CVE-2021-22954 in Concrete CMS <v9, it is recommended to update to the latest version of the software.
You can find more information about CVE-2021-22954 in the release notes of Concrete CMS <v9.