Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-m87h-jxr6-f82w: Concrete CMS allows unauthorized access because directories can be created with insecure permissions

Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creation functions (such as the Mkdir() function) gives universal access (0777) to created folders by default. Excessive permissions can be granted when creating a directory with permissions greater than 0755 or when the permissions argument is not specified.

ghsa
#vulnerability#git#auth

Skip to content

    • Actions

      Automate any workflow

    • Packages

      Host and manage packages

    • Security

      Find and fix vulnerabilities

    • Codespaces

      Instant dev environments

    • Copilot

      Write better code with AI

    • Code review

      Manage code changes

    • Issues

      Plan and track work

    • Discussions

      Collaborate outside of code

    • GitHub Sponsors

      Fund open source developers

*   The ReadME Project
    
    GitHub community articles
  • Pricing
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2023-48648

Concrete CMS allows unauthorized access because directories can be created with insecure permissions

Moderate severity GitHub Reviewed Published Nov 17, 2023 to the GitHub Advisory Database • Updated Nov 17, 2023

Package

composer concrete5/concrete5 (Composer)

Affected versions

< 8.5.13

>= 9.0.0, < 9.2.2

Patched versions

8.5.13

9.2.2

Description

Published to the GitHub Advisory Database

Nov 17, 2023

Last updated

Nov 17, 2023

ghsa: Latest News

GHSA-x7m9-mv49-fv73: Vaultwarden vulnerable to user impersonation