CVE-2021-22967
Exposure of sensitive information in concrete5/core
EPSS 1.1%
Description
In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to a Conversation.To remediate this, a check was added to verify a user has permissions to view files before attaching the files to a message in "add / edit message”.
How to fix CVE-2021-22967
To remediate CVE-2021-22967, upgrade the affected package to a fixed version below.
- Packagist/concrete5/core—upgrade to 8.5.7 or later
Is CVE-2021-22967 being exploited?
Low — EPSS is 1.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 8.5.7