CVE-2023-48648

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-48648
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-48648.json
Aliases
Published
2023-11-17T04:15:07Z
Modified
2023-11-29T10:21:38.312178Z
Details

Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creation functions (such as the Mkdir() function) gives universal access (0777) to created folders by default. Excessive permissions can be granted when creating a directory with permissions greater than 0755 or when the permissions argument is not specified.

References

Affected packages

Git / github.com/concretecms/concretecms

Affected ranges

Type
GIT
Repo
https://github.com/concretecms/concretecms
Events

Affected versions

9.*

9.0.0
9.0.1
9.0.2
9.1.0
9.1.1
9.1.2
9.1.3
9.2.0
9.2.0RC2
9.2.1