8.8
CVSSv3

CVE-2021-22954

Published: 09/02/2022 Updated: 15/02/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an malicious user to make requests on behalf of other users.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

concretecms concrete cms

Github Repositories

Concrete CMS Package: Macareux Security Header Extended

Concrete CMS Package: Macareux Security Header Extended Add security header to mitigate some types of attacks If you consider to mitigate CVE-2021-22954 without editing server configuration, you can use this add-on Ref: CVE-2021-22954 and mitigations below Concrete Version 9 Supported Headers Cross-Origin-Resource-Policy (CORP) Cross-Origin-Opener-Policy (COOP) Cross-Origin-