PT-2026-42772 · Unknown · Concrete Cms
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions prior to 9.5.1
Description
Cross-Site Request Forgery (CSRF) occurs via the
approveVersion() function within the BackendFile class. An attacker can trick a user with edit file contents permissions into publishing a previously uploaded version of a file. This allows for the activation of an unpublished version from a co-editor or a downgrade to an older file version.Recommendations
Update Concrete CMS to version 9.5.1 or later.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms