PT-2022-27048 · Unknown · Concrete Cms
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions below 8.5.10
Concrete CMS versions 9.0.0 through 9.1.2
Description
The issue is related to Reflected XSS in the multilingual report due to un-sanitized output.
Recommendations
For Concrete CMS versions below 8.5.10, update to Concrete CMS 8.5.10 or later.
For Concrete CMS versions 9.0.0 through 9.1.2, update to Concrete CMS 9.1.3 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms