Lucene search

K
osvGoogleOSV:GHSA-J4MV-2RV7-V2J9
HistoryNov 23, 2021 - 6:18 p.m.

Improper Privilege Management in Concrete CMS

2021-11-2318:18:07
Google
osv.dev
7

0.001 Low

EPSS

Percentile

42.8%

Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted “view” permissions on the bulkupdate page, then users in that group can escalate to being an administrator with a specially crafted curl. Fixed by adding a check for group permissions before allowing a group to be moved.

0.001 Low

EPSS

Percentile

42.8%

Related for OSV:GHSA-J4MV-2RV7-V2J9