CVE-2021-22949

A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: “Solar Security CMS Research Team”

Summary:

A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: “Solar Security CMS Research Team”

Reference Links(if available):

  • https://hackerone.com/reports/1102225
  • https://documentation.concretecms.org/developers/introduction/version-history/856-release-notes
  • CVSS Score (if available)

    v2: / MEDIUM

    v3: /

    Links to Exploits(if available)