Security Advisory

CVE-2021-40101

7.2
HIGH

Vulnerability Description

An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.
Published Date November 30, 2021
Official Source NIST NVD Advisory