Show filters
182 Total Results
Displaying 101-110 of 182
Sort by:
Attacker Value
Unknown
CVE-2021-40097
Disclosure Date: September 27, 2021 (last updated February 23, 2025)
An issue was discovered in Concrete CMS through 8.5.5. Authenticated path traversal leads to to remote code execution via uploaded PHP code, related to the bFilename parameter.
0
Attacker Value
Unknown
CVE-2021-40106
Disclosure Date: September 27, 2021 (last updated February 23, 2025)
An issue was discovered in Concrete CMS through 8.5.5. There is unauthenticated stored XSS in blog comments via the website field.
0
Attacker Value
Unknown
CVE-2021-40104
Disclosure Date: September 27, 2021 (last updated November 28, 2024)
An issue was discovered in Concrete CMS through 8.5.5. There is an SVG sanitizer bypass.
0
Attacker Value
Unknown
CVE-2021-40105
Disclosure Date: September 27, 2021 (last updated February 23, 2025)
An issue was discovered in Concrete CMS through 8.5.5. There is XSS via Markdown Comments.
0
Attacker Value
Unknown
CVE-2021-40103
Disclosure Date: September 27, 2021 (last updated February 23, 2025)
An issue was discovered in Concrete CMS through 8.5.5. Path Traversal can lead to Arbitrary File Reading and SSRF.
0
Attacker Value
Unknown
CVE-2021-40098
Disclosure Date: September 27, 2021 (last updated February 23, 2025)
An issue was discovered in Concrete CMS through 8.5.5. Path Traversal leading to RCE via external form by adding a regular expression.
0
Attacker Value
Unknown
CVE-2021-40099
Disclosure Date: September 24, 2021 (last updated November 28, 2024)
An issue was discovered in Concrete CMS through 8.5.5. Fetching the update json scheme over HTTP leads to remote code execution.
0
Attacker Value
Unknown
CVE-2021-40102
Disclosure Date: September 24, 2021 (last updated February 23, 2025)
An issue was discovered in Concrete CMS through 8.5.5. Arbitrary File deletion can occur via PHAR deserialization in is_dir (PHP Object Injection associated with the __wakeup magic method).
0
Attacker Value
Unknown
CVE-2021-40100
Disclosure Date: September 24, 2021 (last updated February 23, 2025)
An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversation Editor is set to Rich Text.
0
Attacker Value
Unknown
CVE-2021-22949
Disclosure Date: September 23, 2021 (last updated February 23, 2025)
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security CMS Research Team"
0