First published: Tue Nov 30 2021(Updated: )
An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Concretecms Concrete Cms | <8.5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40101 is an issue discovered in Concrete CMS before version 8.5.7, where the Dashboard allows a user's password to be changed without a prompt for the current password.
CVE-2021-40101 allows an attacker to change a user's password without requiring knowledge of the current password, potentially leading to unauthorized access.
CVE-2021-40101 has a severity value of 7.2, indicating a high severity vulnerability.
To fix CVE-2021-40101, it is recommended to update Concrete CMS to version 8.5.7 or later, which resolves the issue.
You can find more information about CVE-2021-40101 in the release notes for Concrete CMS version 8.5.7 and the HackerOne report linked in the references.