CVE-2017-8082
concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the…
Does this matter?
Lower severity and a low EPSS score (1.20%). Track it; it rarely justifies an emergency change on its own.
Description
concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the /tools/required/files/importers/imageeditor?fID=1&imgData= URI. This results in a site-wide denial of service making the site not accessible to any users or any administrators.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 1.20% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- concretecms/concrete cms
- Source
- cve@mitre.org
References
- http://zeroday.insecurity.zone/exploits/concrete5_csrf_dos.txtExploit, Third Party Advisory
- https://drive.google.com/open?id=0B3vXUYdNMECWZTd3SFRnUjllWk0Exploit
- https://twitter.com/insecurity/status/856066923146215425Third Party Advisory
- http://zeroday.insecurity.zone/exploits/concrete5_csrf_dos.txtExploit, Third Party Advisory
- https://drive.google.com/open?id=0B3vXUYdNMECWZTd3SFRnUjllWk0Exploit
- https://twitter.com/insecurity/status/856066923146215425Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.