CVE-2022-43689

MEDIUM

Concrete CMS <8.5.10, 9.0.0-9.1.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XXE based DNS requests leading to IP disclosure.

Scores

CVSS v3 5.3
EPSS 0.0065
EPSS Percentile 46.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (2)
concrete5/concrete5 0 - 8.5.10Packagist
concretecms/concrete_cms < 8.5.10
Published Nov 14, 2022
Tracked Since Feb 18, 2026