Critical severity9.8NVD Advisory· Published Nov 17, 2023· Updated Jun 17, 2026
CVE-2023-48648
CVE-2023-48648
Description
Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creation functions (such as the Mkdir() function) gives universal access (0777) to created folders by default. Excessive permissions can be granted when creating a directory with permissions greater than 0755 or when the permissions argument is not specified.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
concrete5/concrete5Packagist | < 8.5.13 | 8.5.13 |
concrete5/concrete5Packagist | >= 9.0.0, < 9.2.2 | 9.2.2 |
Affected products
2- Concrete CMS/Concrete CMSdescription
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-m87h-jxr6-f82wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-48648ghsaADVISORY
- www.concretecms.org/about/project-news/security/2023-11-09-security-blog-about-updated-cves-and-new-releasenvdRelease NotesVendor AdvisoryWEB
- documentation.concretecms.org/developers/introduction/version-history/8513-release-notesnvdRelease NotesWEB
- documentation.concretecms.org/developers/introduction/version-history/922-release-notesnvdRelease NotesWEB
- github.com/concretecms/concretecms/commit/707b974826b761dda5c0baaf345c8582157d9307ghsaWEB
- github.com/concretecms/concretecms/commit/eb882681a0ed19798a8f689d257af8dfe2f3a279ghsaWEB
- github.com/concretecms/concretecms/pull/11677ghsaWEB
News mentions
0No linked articles in our index yet.