CVE-2021-22966 Information
Description
Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted iew\ permissions on the bulkupdate page then users in that group can escalate to being an administrator with a specially crafted curl. Fixed by adding a check for group permissions before allowing a group to be moved. Concrete CMS Security team CVSS scoring: 7.1 AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HCredit for discovery: \Adrian Tiron from FORTBRIDGE ( https://www.fortbridge.co.uk/ )\This fix is also in Concrete version 9.0.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://hackerone.com/reports/1362747
https://documentation.concretecms.org/developers/introduction/version-history/857-release-notes
Privilege
escalation
from
Editor
to
Admin
using
Groups
in
Concrete
CMS
versions
8.5.6
and
below.
If
a
group
is
granted
iew
permissions
on
the
bulkupdate
page
then
users
in
that
group
can
escalate
to
being
an
administrator
with
a
specially
crafted
curl.
Fixed
by
adding
a
check
for
group
permissions
before
allowing
a
group
to
be
moved.
Concrete
CMS
Security
team
CVSS
scoring:
7.1
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HCredit
for
discovery:
\Adrian
Tiron
from
FORTBRIDGE
(
https://www.fortbridge.co.uk/
)\This
fix
is
also
in
Concrete
version
9.0.0
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: