CVE-2021-22967
Last modified
CVE-2021-22967 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to a Conversation.To remediate this, a check was added to verify a user has permissions to view files before attaching the files to a message in "add / edit message”.Concrete CMS security team gave this a CVSS v3.1 score of 4.3 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NCredit for discovery Adrian H. EPSS estimates a 1.11% chance of exploitation in the next 30 days.
Description
In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to a Conversation.To remediate this, a check was added to verify a user has permissions to view files before attaching the files to a message in "add / edit message”.Concrete CMS security team gave this a CVSS v3.1 score of 4.3 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NCredit for discovery Adrian H
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Concretecms | Concrete Cms | < 8.5.7 |
References
- https://documentation.concretecms.org/developers/introduction/version-history/857-release-notesRelease Notes, Vendor Advisory
- https://hackerone.com/reports/869612Permissions Required
- https://documentation.concretecms.org/developers/introduction/version-history/857-release-notesRelease Notes, Vendor Advisory
- https://hackerone.com/reports/869612Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-22967?
How severe is CVE-2021-22967?
How do I fix CVE-2021-22967?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-22961A code injection vulnerability exists within the firewall so…9.8
- CVE-2021-22962An attacker can send a specially crafted request which could…9.1
- CVE-2021-22963A redirect vulnerability in the fastify-static module versio…6.1
- CVE-2021-22964A redirect vulnerability in the `fastify-static` module vers…8.8
- CVE-2021-22965A vulnerability in Pulse Connect Secure before 9.1R12.1 coul…7.5
- CVE-2021-22966Privilege escalation from Editor to Admin using Groups in Co…8.8
- CVE-2021-22968A bypass of adding remote files in Concrete CMS (previously …7.2
- CVE-2021-22969Concrete CMS (formerly concrete5) versions below 8.5.7 has a…5.3
- CVE-2021-2297Vulnerability in the Oracle VM VirtualBox product of Oracle …5.3
- CVE-2021-22970Concrete CMS (formerly concrete5) versions 8.5.6 and below a…7.5
- CVE-2021-22973On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1…7.5
- CVE-2021-22974On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1…7.5
Are you affected by CVE-2021-22967?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
