SB2018070918 - Server-Side Request Forgery (SSRF) in PortlandLabs concrete5



SB2018070918 - Server-Side Request Forgery (SSRF) in PortlandLabs concrete5

Published: July 9, 2018 Updated: August 8, 2020

Security Bulletin ID SB2018070918
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2018-13790)

The vulnerability allows a remote privileged user to execute arbitrary code.

A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network and mapping of the internal network, because of URL functionality on the File Manager page.


Remediation

Install update from vendor's website.