ZeroHour

CVE-2023-28472

CVSS 3.1
5.3 medium
EPSS
<1%p46
Published
()
Modified
Description

Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 does not have Secure and HTTP only attributes set for ccmPoll cookies.

Vendors
concretecms
Products
concrete cms
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.