CVE-2022-43693: CSRF
Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete who use the "out of the box" core OAuth.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-43693?
CVE-2022-43693 is a vulnerability in Concrete CMS that allows Cross-Site Request Forgery (CSRF) due to the lack of a State parameter for external Concrete authentication service.
How does CVE-2022-43693 affect Concrete CMS?
CVE-2022-43693 affects Concrete CMS versions from 8.5.10 to 9.1.2.
What is the severity of CVE-2022-43693?
CVE-2022-43693 has a severity rating of 8.8 (high).
How can I fix CVE-2022-43693 in Concrete CMS?
To fix CVE-2022-43693 in Concrete CMS, it is recommended to update to a version that includes the fix, such as 9.1.3 or later.
Where can I find more information about CVE-2022-43693?
You can find more information about CVE-2022-43693 in the release notes of Concrete CMS versions 8.5.10, 9.1.2, and the official documentation of Concrete CMS.