Описание
ConcreteCMS Cross-site Scripting vulnerability
A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a crafted script to Plural Handle of the Data Objects from System & Settings.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-44765
- https://github.com/concretecms/concretecms/pull/11746
- https://github.com/concretecms/concretecms/pull/11746/commits/0f0564232e0a49719d0bdff6223539b624f116ee
- https://github.com/concretecms/concretecms/pull/11746/commits/92bcc208078571f4beda38cb0952f8e99887737a
- https://github.com/sromanhu/ConcreteCMS-Stored-XSS---Associations
- https://www.concretecms.org/about/project-news/security/2023-11-09-security-blog-about-updated-cves-and-new-release
Пакеты
Наименование
concrete5/concrete5
composer
Затронутые версииВерсия исправления
<= 9.2.1
9.2.2
Связанные уязвимости
CVSS3: 5.4
nvd
больше 2 лет назад
A Cross Site Scripting (XSS) vulnerability in Concrete CMS versions 8.5.12 and below, and 9.0 through 9.2.1 allows an attacker to execute arbitrary code via a crafted script to Plural Handle of the Data Objects from System & Settings.