Unknown · Concrete Cms · CVE-2023-28471
**Name of the Vulnerable Software and Affected Versions**
Concrete CMS (previously concrete5) versions 9.0 through 9.1.3
Concrete CMS (previously concrete5) versions prior to 9.2
**Description**
The issue is related to Stored XSS via a container name. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
**Recommendations**
For versions 9.0 through 9.1.3, update to version 9.2 or later.
For versions prior to 9.2, update to version 9.2 or later.
As a temporary workaround, consider restricting the ability to set container names to minimize the risk of exploitation.