CVE-2023-48648

CRITICAL

Concrete CMS <8.5.13,9.x <9.2.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creation functions (such as the Mkdir() function) gives universal access (0777) to created folders by default. Excessive permissions can be granted when creating a directory with permissions greater than 0755 or when the permissions argument is not specified.

Scores

CVSS v3 9.8
EPSS 0.0123
EPSS Percentile 65.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-276
Status published
Products (2)
concrete5/concrete5 0 - 8.5.13Packagist
concretecms/concrete_cms < 8.5.13
Published Nov 17, 2023
Tracked Since Feb 18, 2026