PT-2021-15302 · Unknown · Concrete Cms
Adrian H
·
Published
2021-11-19
·
Updated
2021-11-23
·
CVE-2021-22967
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions prior to 8.5.7
Description
The issue allows an unauthenticated user to access restricted files if they are allowed to add a message to a conversation. This is due to an Insecure Direct Object Reference (IDOR) vulnerability. To remediate this, a check was added to verify that a user has permissions to view files before attaching them to a message in the "add / edit message" functionality.
Recommendations
For versions prior to 8.5.7, update to version 8.5.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the "add / edit message" functionality to minimize the risk of exploitation. Additionally, ensure that users have the appropriate permissions to view files before allowing them to attach files to messages.
Fix
Information Disclosure
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Concrete Cms