PT-2023-21990 · Unknown · Concrete Cms

·

CVE-2023-28821

·

Published

2023-04-28

·

Updated

2025-01-30

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Concrete CMS (previously concrete5) versions prior to 9.1
Description The issue is related to the lack of a rate limit for password resets in Concrete CMS. This could potentially allow for brute-force attacks on user passwords.
Recommendations For versions prior to 9.1, update to version 9.1 or later to resolve the issue. As a temporary workaround, consider implementing a custom rate limit for password resets until a patch is available. Restrict access to the password reset functionality to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-28821
GHSA-PH6G-6V8W-8P6M

Affected Products

Concrete Cms