Логотип exploitDog
bind:CVE-2022-43695
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-43695

Количество 2

Количество 2

nvd логотип

CVE-2022-43695

около 3 лет назад

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting (XSS) in dashboard/system/express/entities/associations because Concrete CMS allows association with an entity name that doesn’t exist or, if it does exist, contains XSS since it was not properly sanitized. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-8699-h45g-7hm8

больше 2 лет назад

Concrete CMS Cross-site Scripting vulnerability

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-43695

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting (XSS) in dashboard/system/express/entities/associations because Concrete CMS allows association with an entity name that doesn’t exist or, if it does exist, contains XSS since it was not properly sanitized. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.

CVSS3: 4.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-8699-h45g-7hm8

Concrete CMS Cross-site Scripting vulnerability

CVSS3: 4.8
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу