Описание
Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript that executes in the context of any authenticated user visiting the affected account pages. This can lead to session hijacking, credential theft, malicious actions performed on behalf of users, and potential privilege escalation. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.
Ссылки
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 9.0 (включая) до 9.5.1 (исключая)
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 5%
0.00149
Низкий
4.8 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
github
2 месяца назад
Concrete CMS is vulnerable to Stored XSS via page name in the Atomik theme
EPSS
Процентиль: 5%
0.00149
Низкий
4.8 Medium
CVSS3
Дефекты
CWE-79