Security Advisory
CVE-2023-28472
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 does not have Secure and HTTP only attributes set for ccmPoll cookies.