Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q9fm-mpg8-8jqm

Опубликовано: 26 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 2.1

Описание

Concrete CMS is vulnerable to Stored XSS via page name in the Atomik theme

Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript that executes in the context of any authenticated user visiting the affected account pages. This can lead to session hijacking, credential theft, malicious actions performed on behalf of users, and potential privilege escalation. Thanks Yonatan Drori (Tenzai) for reporting.

Пакеты

Наименование

concrete5/concrete5

composer
Затронутые версииВерсия исправления

>= 9.0.0RC.1, < 9.5.1

9.5.1

EPSS

Процентиль: 5%
0.00149
Низкий

2.1 Low

CVSS4

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
2 месяца назад

Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript that executes in the context of any authenticated user visiting the affected account pages. This can lead to session hijacking, credential theft, malicious actions performed on behalf of users, and potential privilege escalation. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.

EPSS

Процентиль: 5%
0.00149
Низкий

2.1 Low

CVSS4

Дефекты

CWE-79