← Back

CVE-2022-43693

nvd nist
Published: Nov 14, 2022Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete who use the "out of the box" core OAuth.

Affected (2)

1 product
Concrete Cms
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Concretecms
Before 8.5.10
From 9.0.0 to 9.1.2

References (10)

Source: cve@mitre.org
PatchRelease NotesThird Party Advisory
Source: cve@mitre.org
PatchRelease NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchRelease NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchRelease NotesThird Party Advisory

Timeline

No history available yet.