Description
An issue was discovered in Concrete CMS through 8.5.5. The Calendar is vulnerable to CSRF. ccm_token is not verified on the ccm/calendar/dialogs/event/add/save endpoint.
Exploits
No known exploits found for this CVE.
Search Exploit-DBReferences
cve@mitre.org
https://documentation.concretecms.org/developers/introduction/version-history/856-release-notescve@mitre.org
https://hackerone.com/reports/1102018af854a3a-2127-422b-91ae-364da2661108
https://documentation.concretecms.org/developers/introduction/version-history/856-release-notesaf854a3a-2127-422b-91ae-364da2661108
https://hackerone.com/reports/1102018