PortlandLabs Concrete Cms是美国PortlandLabs公司的一个面向团队的开源内容管理系统。 PortlandLabs Concrete Cms 存在安全漏洞,该漏洞源于可以通过 HTTP 下载 zip 文件并从这些 zip 文件中执行,攻击者利用该漏洞可能导致 RCE 的代码,以下产品和版本受到影响:Concrete CMS 8.5.7及之前版本,Concrete CMS 9.0 到 9.0.2版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | https://github.com/concrete5/concrete5 | Remediated in Concrete CMS 8.5.8 and 9.1.0. Affected Versions are Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-21231 | 7.5 HIGH | Prototype Pollution |
| CVE-2022-32996 | RootInteractive 安全漏洞 | |
| CVE-2022-34065 | rondolu-yt-concate 安全漏洞 | |
| CVE-2022-34066 | Texercise 安全漏洞 | |
| CVE-2022-34064 | Zibal 安全漏洞 | |
| CVE-2022-33002 | KGExplore 安全漏洞 | |
| CVE-2022-33001 | AAmiles 安全漏洞 | |
| CVE-2022-33000 | AAmiles 安全漏洞 | |
| CVE-2022-32999 | PyPI cloudlabeling 安全漏洞 | |
| CVE-2022-32998 | cryptoasset-data-downloader 安全漏洞 | |
| CVE-2022-32997 | RootInteractive 安全漏洞 | |
| CVE-2022-33003 | watools 安全漏洞 | |
| CVE-2022-33910 | MantisBT 跨站脚本漏洞 | |
| CVE-2022-29578 | Meridian Cooperative Meridian 授权问题漏洞 | |
| CVE-2022-30028 | Dradis 竞争条件问题漏洞 | |
| CVE-2021-39409 | Online Student Rate System 安全漏洞 | |
| CVE-2021-39408 | Online Student Rate System 跨站脚本漏洞 | |
| CVE-2021-42056 | Thales Safenet Authentication Client 后置链接漏洞 | |
| CVE-2021-40893 | validate-data 安全漏洞 | |
| CVE-2022-29330 | VitalPBX 安全特征问题漏洞 |
Showing top 20 of 69 CVEs. View all on vendor page → →
No comments yet