CVE-2022-43689: XEE
Published Nov 14, 2022
·Updated
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XXE based DNS requests leading to IP disclosure.
Affected Software
2 affected components
ConcreteCMS Concrete Cms<8.5.10
ConcreteCMS Concrete Cms>=9.0.0<=9.1.2
Event History
Nov 14, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-43689?
CVE-2022-43689 is a vulnerability in Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 that allows XXE based DNS requests leading to IP disclosure.
2
How severe is CVE-2022-43689?
CVE-2022-43689 has a severity rating of 5.3 (medium).
3
What software versions are affected by CVE-2022-43689?
Concrete CMS versions below 8.5.10 and between 9.0.0 and 9.1.2 are affected by CVE-2022-43689.
4
How can I fix CVE-2022-43689?
To fix CVE-2022-43689, update Concrete CMS to version 8.5.10 or higher or upgrade to a version between 9.1.2 and 9.1.3.
5
Where can I find more information about CVE-2022-43689?
You can find more information about CVE-2022-43689 in the release notes and documentation of Concrete CMS.