VYPR
High severity7.2NVD Advisory· Published Nov 30, 2021· Updated Jun 17, 2026

CVE-2021-40101

CVE-2021-40101

Description

An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*range: <8.5.7
    • (no CPE)range: <8.5.7
  • Concrete CMS/Concrete CMSdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.