CVE-2018-13790

Source
https://cve.org/CVERecord?id=CVE-2018-13790
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-13790.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-13790
Published
2018-07-09T20:29:00.957Z
Modified
2026-07-08T17:57:38.469687Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network and mapping of the internal network, because of URL functionality on the File Manager page.

References

Affected packages

Git / github.com/concretecms/concretecms

Affected ranges

Type
GIT
Repo
https://github.com/concretecms/concretecms
Events
Database specific
{
    "cpe": "cpe:2.3:a:concretecms:concrete_cms:8.2.0:-:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "8.2.0-NA"
        },
        {
            "last_affected": "8.2.0-NA"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

8.*
8.2.0
8.2.0-NA

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-13790.json"