Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes
Vulnerability Description
Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes since administrator entered file attributes are not sufficiently sanitized in the Edit Attributes page. A rogue administrator could put malicious code into the file tags or description attributes and, when another administrator opens the same file for editing, the malicious code could execute. The Concrete CMS Security team scored this 2.4 with CVSS v3 vector AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-1245
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Poto Gabor
References
More from Concrete CMS
View All →Affected Vendor
Concrete CMS
View all reports →