CVE-2017-8082: Concretecms Concrete CMS
Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.
concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the /tools/required/files/importers/imageeditor?fID=1&imgData= URI. This results in a site-wide denial of service making the site not accessible to any users or any administrators.
Affected products
- Concretecms Concrete CMS: version 8.1.0 only
Published 2017-04-24. Last modified 2026-06-17.