CVE-2018-13790

A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network and mapping of the internal network, because of URL functionality on the File Manager page.
References
Link Resource
https://hackerone.com/reports/243865 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:concretecms:concrete_cms:8.2.0:-:*:*:*:*:*:*

History

15 Jul 2021, 20:42

Type Values Removed Values Added
CPE cpe:2.3:a:concrete5:concrete5:8.2.0:-:*:*:*:*:*:* cpe:2.3:a:concretecms:concrete_cms:8.2.0:-:*:*:*:*:*:*

31 Mar 2021, 16:22

Type Values Removed Values Added
CPE cpe:2.3:a:concrete5:concrete5:5.8.2.0:*:*:*:*:*:*:* cpe:2.3:a:concrete5:concrete5:8.2.0:-:*:*:*:*:*:*

Information

Published : 2018-07-09 20:29

Updated : 2023-12-10 12:30


NVD link : CVE-2018-13790

Mitre link : CVE-2018-13790

CVE.ORG link : CVE-2018-13790


JSON object : View

Products Affected

concretecms

  • concrete_cms
CWE
CWE-918

Server-Side Request Forgery (SSRF)