CVE-2021-22970
Server-Side Request Forgery in Concrete CMS
EPSS 1.4%
Description
Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable to SSRF attacks on the private LAN to servers by reading files from the local LAN. An attacker can pivot in the private LAN and exploit local network appsandb.
How to fix CVE-2021-22970
To remediate CVE-2021-22970, upgrade the affected package to a fixed version below.
- Packagist/concrete5/core—upgrade to 8.5.7 or later
Is CVE-2021-22970 being exploited?
Low — EPSS is 1.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 8.5.7