CVE-2021-22958

HIGH8.2EPSS 0.40%

Server-Side Request Forgery vulnerability in concrete5

Published: 10/12/2021Modified: 11/8/2023
Also known as:GHSA-284f-f2hw-j2gx

Description

A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the limitations in place for localhost allowing interaction with local services. Impact can vary depending on services exposed.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

References (5)