Concrete CMS
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*
- < 9.4.8
A cross-site request forgery (CSRF) vulnerability has been identified in Concrete CMS versions prior to 9.4.8. This issue allows a rogue administrator to manipulate the Anti-Spam Allowlist Group Configuration by using the group_id parameter. The vulnerability arises because changes are saved before the CSRF token is validated, leading to a security bypass.
Exploitation of this vulnerability could result in unauthorized changes to group configurations, bypassing CSRF protections.
Users can upgrade to Concrete CMS version 9.4.8 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.