Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7367 | Concrete CMS affected by a stored XSS in Folder Function.The "Add Folder" functionality |
Github GHSA |
GHSA-pvmx-mjmh-jfcx | Concrete CMS affected by a stored XSS in Folder Function.The "Add Folder" functionality |
Thu, 04 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Concretecms
Concretecms concrete Cms |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Concretecms
Concretecms concrete Cms |
|
| Metrics |
cvssV3_1
|
Tue, 11 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Mar 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Concrete CMS versions 9.0.0 through 9.3.9 are affected by a stored XSS in Folder Function.The "Add Folder" functionality lacks input sanitization, allowing a rogue admin to inject XSS payloads as folder names. The Concrete CMS security team gave this vulnerability a CVSS 4.0 Score of 4.8 with vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N. Versions below 9 are not affected. Thanks, Alfin Joseph for reporting. | |
| Title | Stored XSS in Folder Function by Rogue Admin | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ConcreteCMS
Published:
Updated: 2025-03-11T15:38:49.747Z
Reserved: 2025-01-22T23:27:46.011Z
Link: CVE-2025-0660
Updated: 2025-03-11T15:38:34.005Z
Status : Analyzed
Published: 2025-03-10T21:15:40.110
Modified: 2025-09-04T15:54:11.520
Link: CVE-2025-0660
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA