Show filters
99 Total Results
Displaying 81-90 of 99
Sort by:
Attacker Value
Unknown
CVE-2021-22953
Disclosure Date: September 23, 2021 (last updated February 23, 2025)
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security Research Team"
0
Attacker Value
Unknown
CVE-2021-22950
Disclosure Date: September 23, 2021 (last updated February 23, 2025)
Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery: "Solar Security Research Team"
0
Attacker Value
Unknown
CVE-2021-36766
Disclosure Date: July 30, 2021 (last updated February 23, 2025)
Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/dashboard/system/environment/logging.php Logging::update_logging() method. User input passed through the logFile request parameter is not properly sanitized before being used in a call to the file_exists() PHP function. This can be exploited by malicious users to inject arbitrary PHP objects into the application scope (PHP Object Injection via phar:// stream wrapper), allowing them to carry out a variety of attacks, such as executing arbitrary PHP code.
0
Attacker Value
Unknown
CVE-2021-28145
Disclosure Date: March 18, 2021 (last updated February 22, 2025)
Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct XSS attacks via a crafted survey block. This requires at least Editor privileges.
0
Attacker Value
Unknown
CVE-2021-3111
Disclosure Date: January 08, 2021 (last updated February 22, 2025)
The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/view/ URI.
0
Attacker Value
Unknown
CVE-2020-24986
Disclosure Date: September 04, 2020 (last updated February 22, 2025)
Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to modify site configuration to upload the PHP file and execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2020-11476
Disclosure Date: July 28, 2020 (last updated February 21, 2025)
Concrete5 before 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file.
0
Attacker Value
Unknown
CVE-2020-14961
Disclosure Date: June 22, 2020 (last updated November 28, 2024)
Concrete5 before 8.5.3 does not constrain the sort direction to a valid asc or desc value.
0
Attacker Value
Unknown
CVE-2011-3183
Disclosure Date: January 14, 2020 (last updated February 21, 2025)
A Cross-Site Scripting (XSS) vulnerability exists in the rcID parameter in Concrete CMS 5.4.1.1 and earlier.
0
Attacker Value
Unknown
CVE-2018-19146
Disclosure Date: June 17, 2019 (last updated November 27, 2024)
Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTML data with a SCRIPT element.
0