Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qgm9-rxmq-jxmq

Опубликовано: 03 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 3.1

Описание

Concrete CMS Stored XSS in the Search Field

Concrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search Field. Prior to the fix, stored XSS could be executed by an administrator changing a filter to which a rogue administrator had previously added malicious code. The Concrete CMS security team gave this vulnerability a CVSS v3.1 score of 3.1 with a vector of AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator . Thanks Alexey Solovyev for reporting

Пакеты

Наименование

concrete5/concrete5

composer
Затронутые версииВерсия исправления

>= 9.0.0RC1, < 9.2.8

9.2.8

Наименование

concrete5/concrete5

composer
Затронутые версииВерсия исправления

< 8.5.16

8.5.16

EPSS

Процентиль: 29%
0.00104
Низкий

3.1 Low

CVSS3

Дефекты

CWE-20
CWE-79

Связанные уязвимости

CVSS3: 3.1
nvd
почти 2 года назад

Concrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search Field. Prior to the fix, stored XSS could be executed by an administrator changing a filter to which a rogue administrator had previously added malicious code. The Concrete CMS security team gave this vulnerability a CVSS v3.1 score of 3.1 with a vector of AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator . Thanks Alexey Solovyev for reporting

EPSS

Процентиль: 29%
0.00104
Низкий

3.1 Low

CVSS3

Дефекты

CWE-20
CWE-79