CVE-2023-28472 Information

Description

Concrete CMS (previously concrete5) before 9.2 does not have Secure and HTTP only attributes set for ccmPoll cookies.

Reference

https://concretecms.com https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2023-04-20

Share on: