Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9v2g-37mp-qpxf

Опубликовано: 21 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 7.3

Описание

Concrete CMS has Stored XSS through its height parameter

Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $height. Any user with editor privileges can inject malicious JavaScript that executes in the context of any visitor's browser, potentially leading to session hijacking, credential theft, or other malicious actions.

Пакеты

Наименование

concrete5/concrete5

composer
Затронутые версииВерсия исправления

< 9.5.1

9.5.1

EPSS

Процентиль: 2%
0.00122
Низкий

7.3 High

CVSS4

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
2 месяца назад

Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $height. Any user with editor privileges can inject malicious JavaScript that executes in the context of any visitor's browser, potentially leading to session hijacking, credential theft, or other malicious actions. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 7.3 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Alfin Joseph for reporting.

EPSS

Процентиль: 2%
0.00122
Низкий

7.3 High

CVSS4

Дефекты

CWE-79