PT-2023-29284 · Unknown · Concrete Cms

Romanhu

·

Published

2023-10-06

·

Updated

2024-08-02

·

CVE-2023-44760

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Concrete CMS version 9.2.1
Description The issue concerns multiple Cross Site Scripting (XSS) vulnerabilities that allow an attacker to execute arbitrary code via a crafted script. This can be done by exploiting the Header and Footer Tracking Codes of the SEO & Statistics, or the SEO - Extra from Page Settings. The vendor disputes the severity of this issue, stating that the ability to place JavaScript in these areas is an intentional customization feature for admins. However, it's noted that the exploitation method does not provide access to a Concrete CMS session due to the HttpOnly configuration of the session cookie.
Recommendations For Concrete CMS version 9.2.1, consider restricting access to the Header and Footer Tracking Codes of the SEO & Statistics, as well as the SEO - Extra from Page Settings, to minimize the risk of exploitation. Additionally, admins should be cautious when placing custom scripts in these areas to avoid potential security risks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-44760
GHSA-437P-JFM4-2387
GHSA-4QV6-37XQ-MGQ2

Affected Products

Concrete Cms