CVE-2023-48648 | Concrete CMS up to 8.5.12/9.2.1 File Creation Mkdir permission (EUVD-2023-2998)
A vulnerability described as critical has been identified in Concrete CMS up to 8.5.12/9.2.1. Impacted is the function Mkdir of the component File Creation Handler. The manipulation results in permission issues.
This vulnerability is reported as CVE-2023-48648. The attacker must have access to the local network to execute the attack. No exploit exists.
Upgrading the affected component is recommended.