CVE-2023-48653

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Feb 29, 2024
Updated: Dec 16, 2024
CWE ID 352

Summary

CVE-2023-48653 is a vulnerability affecting Concrete CMS versions prior to 8.5.14 and 9 before 9.2.3. This issue permits Cross Site Request Forgery (CSRF) attacks. An attacker can trick an administrator into deleting calendar events on the site due to the sequential and numeric nature of event IDs. Despite the event ID being part of the delete request, an adequate CSRF token validation is missing, making the system susceptible to this type of attack. This weakness poses a serious risk for unauthorized modification of events on the affected Concrete CMS instance.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Concretecms Concrete Cms

Affected Vendors

  • Concrete CMS