CVE-2021-22966
Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.98%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted "view" permissions on the bulkupdate page, then users in that group can escalate to being an administrator with a specially crafted curl. Fixed by adding a check for group permissions before allowing a group to be moved. Concrete CMS Security team CVSS scoring: 7.1 AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HCredit for discovery: "Adrian Tiron from FORTBRIDGE ( https://www.fortbridge.co.uk/ )"This fix is also in Concrete version 9.0.0
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.98% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- concretecms/concrete cms
- Source
- support@hackerone.com
References
- https://documentation.concretecms.org/developers/introduction/version-history/857-release-notesRelease Notes, Vendor Advisory
- https://hackerone.com/reports/1362747Permissions Required
- https://documentation.concretecms.org/developers/introduction/version-history/857-release-notesRelease Notes, Vendor Advisory
- https://hackerone.com/reports/1362747Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.