PT-2021-22815 · Unknown · Concrete Cms

Published

2021-09-27

·

Updated

2021-10-01

·

CVE-2021-40106

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Concrete CMS versions through 8.5.5
Description An issue was discovered in Concrete CMS, where there is unauthenticated stored XSS in blog comments via the website field.
Recommendations For versions through 8.5.5, as a temporary workaround, consider disabling the blog comments feature until a patch is available. Restrict access to the blog comments module to minimize the risk of exploitation. Avoid using the website field in blog comments until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-40106

Affected Products

Concrete Cms