Description
Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/delete/submit. An attacker can force an admin to delete events on the site because the event ID is numeric and sequential.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3rxx-8f33-7p6p | Concrete CMS Cross Site Request Forgery (CSRF) vulnerability |
References
History
Mon, 16 Dec 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Concretecms
Concretecms concrete Cms |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Concretecms
Concretecms concrete Cms |
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T21:37:54.234Z
Reserved: 2023-11-17T00:00:00.000Z
Link: CVE-2023-48653
Updated: 2024-08-02T21:37:54.234Z
Status : Analyzed
Published: 2024-02-29T01:41:34.160
Modified: 2024-12-16T19:11:44.093
Link: CVE-2023-48653
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA