PT-2026-42580 · Unknown · Concrete Cms
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions 9.5.0 and earlier
Description
The RSS Displayer block accepts a feed URL from page editors and fetches it server-side without proper validation. This lack of validation allows for redirect-to-internal bypasses, where an attacker can potentially redirect requests to internal resources.
Recommendations
Update to a version later than 9.5.0.
As a temporary workaround, restrict access to the RSS Displayer block for untrusted page editors.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms