CVE-2022-43693
Summary
| CVE | CVE-2022-43693 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-14 17:15:00 UTC |
| Updated | 2022-11-17 21:55:00 UTC |
| Description | Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete who use the "out of the box" core OAuth. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Concretecms | Concrete Cms | All | All | All | All |
| Application | Concretecms | Concrete Cms | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release 9.1.3 · concretecms/concretecms · GitHub | MISC | github.com | |
| Release 8.5.10 · concretecms/concretecms · GitHub | MISC | github.com | |
| Concrete CMS Security Advisory 2022-10-31 | MISC | www.concretecms.org | |
| 9.1.3 Release Notes :: Concrete CMS | MISC | documentation.concretecms.org | |
| 8.5.10-12 Release Notes :: Concrete CMS | MISC | documentation.concretecms.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.