PT-2024-17599 · Unknown · Concrete Cms
Poto Gabor
·
Published
2024-02-09
·
Updated
2024-02-15
·
CVE-2024-1245
CVSS v3.1
2.4
Low
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS version 9 before 9.2.5
Description
The issue concerns stored XSS in file tags and description attributes. Administrator-entered file attributes are not sufficiently sanitized in the Edit Attributes page, allowing a rogue administrator to put malicious code into the file tags or description attributes. This malicious code could execute when another administrator opens the same file for editing.
Recommendations
For Concrete CMS version 9 before 9.2.5, update to version 9.2.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the Edit Attributes page to minimize the risk of exploitation. Additionally, avoid using unsanitized input from administrator-entered file attributes in the file tags or description attributes until the issue is resolved.
Fix
XSS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Concrete Cms