Логотип exploitDog
bind:CVE-2023-44760
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-44760

Количество 2

Количество 2

nvd логотип

CVE-2023-44760

больше 2 лет назад

Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS v.9.2.1 allow an attacker to execute arbitrary code via a crafted script to the Header and Footer Tracking Codes of the SEO & Statistics. NOTE: the vendor disputes this because these header/footer changes can only be made by an admin, and allowing an admin to place JavaScript there is an intentional customization feature. Also, the exploitation method claimed by "sromanhu" does not provide any access to a Concrete CMS session, because the Concrete CMS session cookie is configured as HttpOnly.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-4qv6-37xq-mgq2

больше 2 лет назад

Concrete CMS Cross-site Scripting vulnerability

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-44760

Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS v.9.2.1 allow an attacker to execute arbitrary code via a crafted script to the Header and Footer Tracking Codes of the SEO & Statistics. NOTE: the vendor disputes this because these header/footer changes can only be made by an admin, and allowing an admin to place JavaScript there is an intentional customization feature. Also, the exploitation method claimed by "sromanhu" does not provide any access to a Concrete CMS session, because the Concrete CMS session cookie is configured as HttpOnly.

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4qv6-37xq-mgq2

Concrete CMS Cross-site Scripting vulnerability

CVSS3: 5.4
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу