PT-2023-21989 · Unknown · Concrete Cms

Published

2023-04-28

·

Updated

2025-01-31

·

CVE-2023-28820

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Concrete CMS (previously concrete5) versions prior to 9.1
Description The issue concerns stored XSS in the RSS Displayer via the href attribute. This occurs because the link element input was not sanitized, allowing for potential exploitation.
Recommendations For versions prior to 9.1, update to version 9.1 or later to resolve the issue. As a temporary workaround, consider disabling the RSS Displayer feature until a patch is available. Restrict access to the RSS Displayer module to minimize the risk of exploitation. Avoid using the href attribute in the RSS Displayer until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-28820
GHSA-FGXJ-G7X3-85CQ

Affected Products

Concrete Cms