Security Advisory

CVE-2023-28472

5.3
MEDIUM

Vulnerability Description

Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 does not have Secure and HTTP only attributes set for ccmPoll cookies.
Published Date April 28, 2023
Official Source NIST NVD Advisory