Concrete CMS
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*
- <= 9.5.0
An authorization bypass vulnerability has been identified in the Calendar Event Frontend Dialog of Concrete CMS versions through 9.5.0. This vulnerability can lead to unauthorized access to private calendar data by exploiting a public calendar block as a pivot point. The issue allows cross-calendar data disclosure, where private calendar information can be accessed through a publicly shared calendar.
Exploitation of this vulnerability could result in unauthorized access to private calendar data, allowing cross-calendar data disclosure.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.