CVE-2023-48648
Last modified
CVE-2023-48648 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creation functions (such as the Mkdir() function) gives universal access (0777) to created folders by default. EPSS estimates a 1.23% chance of exploitation in the next 30 days.
Description
Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creation functions (such as the Mkdir() function) gives universal access (0777) to created folders by default. Excessive permissions can be granted when creating a directory with permissions greater than 0755 or when the permissions argument is not specified.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Concretecms | Concrete Cms | < 8.5.13 |
| Concretecms | Concrete Cms | >= 9.0, < 9.2.2 |
References
- https://www.concretecms.org/about/project-news/security/2023-11-09-security-blog-about-updated-cves-and-new-releaseRelease Notes, Vendor Advisory
- https://www.concretecms.org/about/project-news/security/2023-11-09-security-blog-about-updated-cves-and-new-releaseRelease Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-48648?
How severe is CVE-2023-48648?
How do I fix CVE-2023-48648?
Are you affected by CVE-2023-48648?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
