-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from missing rate limiting in password reset handling. In MVC frameworks like Concrete CMS, this would typically be implemented in the controller method processing the reset request. The advisory explicitly states the fix required a new library added in 9.1.0, indicating the vulnerable code was in the pre-patch password reset submission handler. While exact commit details aren't provided, the controller action managing password resets (commonly ForgotPassword::submit) is the logical location for this security control gap.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| concrete5/concrete5 | composer | < 9.1.0 | 9.1.0 |
Ongoing coverage of React2Shell