CVE-2022-43689

MEDIUM5.3EPSS 0.29%

Concrete CMS vulnerable to XML External Entity

Published: 11/15/2022Modified: 11/8/2023
Also known as:GHSA-q48r-xg9h-78m8

Description

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XXE based DNS requests leading to IP disclosure.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References (7)