A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other users.Referenceshttps://documentation.concretecms.org/developers/introduction/version-history/90-release-notes