Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0600 | Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature due to insufficient validation of administrator provided data. A rogue administrator could inject malicious code when importing images, leading to the execution of the malicious code on the website user’s browser. The Concrete CMS Security team scored this 2 with CVSS v3 vector AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N. This does not affect Concrete versions prior to version 9. |
Github GHSA |
GHSA-9v3w-cj7m-qh5g | Concrete CMS vulnerable to reflected XSS via the Image URL Import Feature |
Thu, 24 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: ConcreteCMS
Published:
Updated: 2025-04-24T15:46:51.612Z
Reserved: 2024-02-06T00:50:59.480Z
Link: CVE-2024-1246
Updated: 2024-08-01T18:33:25.494Z
Status : Modified
Published: 2024-02-09T20:15:54.573
Modified: 2024-11-21T08:50:08.877
Link: CVE-2024-1246
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA