First published: Fri Apr 28 2023(Updated: )
Concrete CMS (previously concrete5) before 9.2 does not have Secure and HTTP only attributes set for ccmPoll cookies.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Concretecms Concrete Cms | <9.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28472 is a vulnerability in Concrete CMS (previously concrete5) before 9.2 where the Secure and HTTP only attributes are not set for ccmPoll cookies.
CVE-2023-28472 has a severity rating of medium with a CVSS score of 5.3.
CVE-2023-28472 affects Concrete CMS versions before 9.2 by not setting the Secure and HTTP only attributes for ccmPoll cookies.
To fix CVE-2023-28472, it is recommended to update Concrete CMS to version 9.2 or later, where the Secure and HTTP only attributes are properly set for ccmPoll cookies.
You can find more information about CVE-2023-28472 at the following references: - [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-28472) - [Concrete CMS](https://concretecms.com) - [Concrete CMS Security Advisory](https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2023-04-20)