CVE-2021-40104: High severity ConcreteCMS Concrete CMS vulnerability
Published Sep 27, 2021
·Updated
An issue was discovered in Concrete CMS through 8.5.5. There is an SVG sanitizer bypass.
Affected Software
1 affected component
ConcreteCMS Concrete CMS<=8.5.5
Event History
Sep 27, 2021
CVE Published
via MITRE·11:56 AM
Data Sourced
via MITRE·11:56 AM
Description
Data Sourced
via NVD·12:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2021-40104?
CVE-2021-40104 is a vulnerability in Concrete CMS through version 8.5.5 that allows for an SVG sanitizer bypass.
2
How severe is CVE-2021-40104?
CVE-2021-40104 has a severity rating of 7.5 (high).
3
What software versions are affected by CVE-2021-40104?
CVE-2021-40104 affects Concrete CMS versions up to and including 8.5.5.
4
How can I fix CVE-2021-40104?
To fix CVE-2021-40104, update your Concrete CMS installation to version 8.5.6 or later.
5
Where can I find more information about CVE-2021-40104?
You can find more information about CVE-2021-40104 in the release notes for Concrete CMS version 8.5.6 and the associated HackerOne report.