Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete who use the "out of the box" core OAuth.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/concretecms/concretecms/releases/9.1.3 | patch third party advisory release notes |
https://github.com/concretecms/concretecms/releases/8.5.10 | patch third party advisory release notes |
https://documentation.concretecms.org/developers/introduction/version-history/913-release-notes | release notes vendor advisory |
https://documentation.concretecms.org/developers/introduction/version-history/8510-release-notes | release notes vendor advisory |
https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2022-10-31 | vendor advisory |