First published: Mon Sep 27 2021(Updated: )
An issue was discovered in Concrete CMS through 8.5.5. The Calendar is vulnerable to CSRF. ccm_token is not verified on the ccm/calendar/dialogs/event/add/save endpoint.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Concretecms Concrete Cms | <8.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-40108.
The severity of CVE-2021-40108 is high with a severity score of 8.8.
This vulnerability affects Concrete CMS versions up to 8.5.6.
Yes, the Calendar in Concrete CMS is vulnerable to CSRF.
To fix the vulnerability in Concrete CMS, you should update to version 8.5.6 or later.