Concrete CMS affected by a stored XSS in Folder Function.The "Add Folder" functionality
Moderate severity
GitHub Reviewed
Published
Mar 10, 2025
to the GitHub Advisory Database
•
Updated Mar 10, 2025
Description
Published by the National Vulnerability Database
Mar 10, 2025
Published to the GitHub Advisory Database
Mar 10, 2025
Reviewed
Mar 10, 2025
Last updated
Mar 10, 2025
Concrete CMS versions 9.0.0 through 9.3.9 are affected by a stored XSS in Folder Function.The "Add Folder" functionality lacks input sanitization, allowing a rogue admin to inject XSS payloads as folder names. The Concrete CMS security team gave this vulnerability a CVSS 4.0 Score of 4.8 with vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N. Versions below 9 are not affected. Thanks, Alfin Joseph for reporting.
References