OSV 1.4.0 · github-reviewed · 修改于 2026-06-25 02:28
发布时间
2026-05-22 05:30
GitHub 审查时间
2026-06-25 02:28
NVD 发布时间
2026-05-22 05:16
源文件
advisories/github-reviewed/2026/05/GHSA-jr5g-qv3g-rxxx/GHSA-jr5g-qv3g-rxxx.json
Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/do_update/<pkgHandle>. The do_update() method in concrete/controllers/single_page/dashboard/extend/update.php checks only canInstallPackages() before executing upgradeCoreData() and upgrade() on the named package's controller. Because the endpoint is a state-changing GET route with no token enforcement, an attacker can force an authenticated administrator to trigger a package upgrade via a single cross-site navigation.In order to be vulnerable, the victim must be passing canInstallPackages() and and a target package must already be already installed. The Concrete CMS security team thanks @maru1009 for reporting this issue.