Description
Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS via the Role Name field since there is insufficient validation of administrator provided data for that field. A rogue administrator could inject malicious code into the Role Name field which might be executed when users visit the affected page. The Concrete CMS Security team scored this 2 with CVSS v3 vector AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator . Concrete versions below 9 do not include group types so they are not affected by this vulnerability.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0690 | Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS via the Role Name field since there is insufficient validation of administrator provided data for that field. A rogue administrator could inject malicious code into the Role Name field which might be executed when users visit the affected page. The Concrete CMS Security team scored this 2 with CVSS v3 vector AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator . Concrete versions below 9 do not include group types so they are not affected by this vulnerability. |
Github GHSA |
GHSA-q25h-jch8-gfrp | Concrete CMS vulnerable to stored XSS via the Role Name field |
References
History
No history.
Status: PUBLISHED
Assigner: ConcreteCMS
Published:
Updated: 2024-08-01T18:33:25.343Z
Reserved: 2024-02-06T00:51:01.240Z
Link: CVE-2024-1247
Updated: 2024-08-01T18:33:25.343Z
Status : Modified
Published: 2024-02-09T19:15:24.183
Modified: 2024-11-21T08:50:09.013
Link: CVE-2024-1247
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA