CVE-2022-30117

CRITICAL

Concrete CMS < 8.5.8 and 9.0.0-9.0.2 - Authenticated Path Traversal and Arbitrary File Delete via File Upload Endpoint

Title source: llm
STIX 2.1

Description

Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 allow traversal in /index.php/ccm/system/file/upload which could result in an Arbitrary File Delete exploit. This was remediated by sanitizing /index.php/ccm/system/file/upload to ensure Concrete doesn’t allow traversal and by changing isFullChunkFilePresent to have an early false return when input doesn't match expectations.Concrete CMS Security team ranked this 5.8 with CVSS v3.1 vector AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H. Credit to Siebene for reporting.

References (3)

Core 3
Core References
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1482280

Scores

CVSS v3 9.1
EPSS 0.0202
EPSS Percentile 78.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-22
Status published
Products (2)
concrete5/core 9.0.0 - 9.1.0Packagist
concretecms/concrete_cms < 8.5.8
Published Jun 24, 2022
Tracked Since Feb 18, 2026