Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-40109
HistorySep 27, 2021 - 1:15 p.m.

Server side request forgery (ssrf)

2021-09-2713:15:00
PRIOn knowledge base
www.prio-n.com
5

6.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.7%

A SSRF issue was discovered in Concrete CMS through 8.5.5. Users can access forbidden files on their local network. A user with permissions to upload files from external sites can upload a URL that redirects to an internal resource of any file type. The redirect is followed and loads the contents of the file from the redirected-to server. Files of disallowed types can be uploaded.

CPENameOperatorVersion
concrete_cmslt8.5.6

6.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.7%

Related for PRION:CVE-2021-40109