PT-2026-22865 · Unknown · Concrete Cms

Minhnn42

+2

·

Publicado

2026-03-04

·

Atualizado

2026-03-04

·

CVE-2026-3240

CVSS v3.1

4.8

Média

VetorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Concrete CMS versions prior to 9.4.8
Description A user with edit permissions on a page containing a Legacy form can execute a stored Cross-Site Scripting (XSS) attack targeting high-privilege accounts through the Question field. This allows an attacker to inject malicious scripts that execute within the context of another user's browser.
Recommendations Update to version 9.4.8 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3240
GHSA-45FJ-FVMM-XCC5

Produtos afetados

Concrete Cms