CVE-2023-28821 Information

Description

Concrete CMS (previously concrete5) before 9.1 did not have a rate limit for password resets.

Reference

https://github.com/concretecms/concretecms/releases https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2023-04-20

Share on: