CVE-2021-22954: CSRF
Published Feb 9, 2022
·Updated
A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other users.
Affected Software
1 affected component
ConcreteCMS Concrete CMS<9.0
Event History
Feb 9, 2022
CVE Published
via MITRE·10:05 PM
Data Sourced
via MITRE·10:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-22954?
CVE-2021-22954 is a cross-site request forgery vulnerability in Concrete CMS <v9.
2
How does CVE-2021-22954 affect Concrete CMS?
CVE-2021-22954 allows an attacker to make requests on behalf of other users in Concrete CMS <v9.
3
What is the severity of CVE-2021-22954?
CVE-2021-22954 has a severity rating of 8.8 (high).
4
How can I fix CVE-2021-22954 in Concrete CMS?
To fix CVE-2021-22954 in Concrete CMS <v9, it is recommended to update to the latest version of the software.
5
Where can I find more information about CVE-2021-22954?
You can find more information about CVE-2021-22954 in the release notes of Concrete CMS <v9.