HIGH
Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete who use the "out of the box" core OAuth
Published Nov 14, 2022
8.8
HIGHCVSS 3.1
EPSS 0.48%
Description
Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete who use the "out of the box" core OAuth.
Affected products
No data.
OR
- < 8.5.10
- ≥ 9.0.0 · ≤ 9.1.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://documentation.concretecms.org/developers/introduction/version-history/8510-release-notes Release NotesVendor Advisory
- https://documentation.concretecms.org/developers/introduction/version-history/913-release-notes Release NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7449 Advisory
- https://github.com/advisories/GHSA-w8fp-3gwq-gxpw Advisory
- https://github.com/concretecms/concretecms/releases/8.5.10 PatchRelease NotesThird Party Advisory
- https://github.com/concretecms/concretecms/releases/9.1.3 PatchRelease NotesThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-43693
- https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2022-10-31 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://documentation.concretecms.org/developers/introduction/version-history/8510-release-notes | Release NotesVendor Advisory | |
| https://documentation.concretecms.org/developers/introduction/version-history/913-release-notes | Release NotesVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7449 | Advisory | |
| https://github.com/advisories/GHSA-w8fp-3gwq-gxpw | Advisory | |
| https://github.com/concretecms/concretecms/releases/8.5.10 | PatchRelease NotesThird Party Advisory | |
| https://github.com/concretecms/concretecms/releases/9.1.3 | PatchRelease NotesThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-43693 | ||
| https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2022-10-31 | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 14, 2022
Updated Apr 30, 2025
Reserved Oct 24, 2022
Link CVE-2022-43693
CISA Vulnrichment
Updated Apr 30, 2025
ENISA EUVD
EUVD-2022-7449 GHSA-W8FP-3GWQ-GXPW Assigner mitre
Published Nov 14, 2022
Updated Apr 30, 2025
Exploited since n/a
Link EUVD-2022-7449