OSV 1.4.0 · github-reviewed · 修改于 2026-06-25 04:57
发布时间
2026-05-22 05:30
GitHub 审查时间
2026-06-25 02:12
NVD 发布时间
2026-05-22 05:16
源文件
advisories/github-reviewed/2026/05/GHSA-x2fp-hj8c-mmxh/GHSA-x2fp-hj8c-mmxh.json
Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow cross-calendar data disclosure. A public calendar block can be used as a pivot point to access private calendar data.