PT-2023-29290 · Unknown · Concrete Cms
Romanhu
·
Published
2023-10-06
·
Updated
2024-08-02
·
CVE-2023-44766
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS version 9.2.1
Description
A Cross Site Scripting (XSS) issue allows an attacker to execute arbitrary code via a crafted script to the SEO - Extra from Page Settings. Note that the vendor disputes this, stating that allowing an admin to place JavaScript there is an intentional customization feature.
Recommendations
For Concrete CMS version 9.2.1, consider restricting access to the SEO - Extra from Page Settings to minimize the risk of exploitation, as this feature can be used to execute arbitrary code. Additionally, ensure that only trusted administrators have access to this feature, as the vendor intends it for customization purposes. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms