CVE-2017-18195

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/02/2018
Last modified:
01/11/2021

Description

An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enumerate comments from all blog posts by POSTing requests to /index.php/tools/required/conversations/view_ajax with incremental 'cnvID' integers.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:* 8.3.0 (excluding)