Lucene search

K
cvelistMitreCVELIST:CVE-2023-48652
HistoryDec 25, 2023 - 12:00 a.m.

CVE-2023-48652

2023-12-2500:00:00
mitre
www.cve.org
1
concrete cms 9.2.3
cross site request forgery
csrf
server report logs
web application
admin user
authenticated

4.9 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.0%

Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) via /ccm/system/dialogs/logs/delete_all/submit. An attacker can force an admin user to delete server report logs on a web application to which they are currently authenticated.

4.9 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.0%

Related for CVELIST:CVE-2023-48652