Loading HuntDB...

GHSA-935f-hm9p-8j6v

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the /tools/required/files/importers/imageeditor?fID=1&imgData= URI. This results in a site-wide denial of service making the site not accessible to any users or any administrators.

Related CVEs

Key Information

GHSA ID
GHSA-935f-hm9p-8j6v
Published
May 13, 2022 1:08 AM
Last Modified
May 13, 2022 1:08 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 31, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.