Vulnerability CVE-2023-48653


Published: 2024-02-29

Description:
Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/delete/submit. An attacker can force an admin to delete events on the site because the event ID is numeric and sequential.

 References:
https://documentation.concretecms.org/developers/introduction/version-history/923-release-notes
https://www.concretecms.org/about/project-news/security/2023-12-05-concrete-cms-new-cves-and-cve-updates

Copyright 2026, cxsecurity.com

 

Back to Top