CVE-2026-8337
Concrete CMS is vulnerable to IDOR in surveys
EPSS 0.19%
描述
Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in such a way that both public and private surveys are present on the site. An unauthenticated attacker can vote in the restricted survey by submitting the restricted optionID through the public survey’s endpoint.
如何修補 CVE-2026-8337
要修補 CVE-2026-8337,請將受影響套件升級到下列已修補版本。
- Packagist/concrete5/concrete5—升級至 9.5.1 或更新版本
CVE-2026-8337 正在被利用嗎?
低 — EPSS 為 0.2%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 9.5.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |