Concrete CMS 版本 8.3.0 至 9.5.2 在日历事件编辑对话框(concrete/controllers/dialog/event/edit.php)中存在一个授权绕过漏洞。该对话框在检查权限时,依据的是请求中提供的日历标识符,而非目标事件所属的日历。因此,拥有单个日历上“添加事件”权限的用户,能够读取并覆盖其无权访问的其他日历中的事件,并且可以删除该事件原始的本地实例。将注入的版本发布到线上日历(此操作会使先前已批准版本降级),此外还需要操作者具备 approve_calendar_event
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Concrete CMS | Concrete CMS | 8.3.0≤ 9.5.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 8.3.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet