Логотип exploitDog
bind:CVE-2022-43556
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-43556

Количество 2

Количество 2

nvd логотип

CVE-2022-43556

около 3 лет назад

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XSS in the text input field since the result dashboard page output is not sanitized. The Concrete CMS security team has ranked this 4.2 with CVSS v3.1 vector AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N Thanks @_akbar_jafarli_ for reporting. Remediate by updating to Concrete CMS 8.5.10 and Concrete CMS 9.1.3.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xj33-8r43-r227

около 3 лет назад

Concrete CMS vulnerable to cross-site scripting in the text input field

CVSS3: 4.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-43556

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XSS in the text input field since the result dashboard page output is not sanitized. The Concrete CMS security team has ranked this 4.2 with CVSS v3.1 vector AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N Thanks @_akbar_jafarli_ for reporting. Remediate by updating to Concrete CMS 8.5.10 and Concrete CMS 9.1.3.

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-xj33-8r43-r227

Concrete CMS vulnerable to cross-site scripting in the text input field

CVSS3: 4.2
1%
Низкий
около 3 лет назад

Уязвимостей на страницу