PT-2024-17603 · Unknown · Concrete Cms
Cupc4K3
·
Published
2024-02-09
·
Updated
2024-02-15
·
CVE-2024-1246
CVSS v3.1
2.0
Low
| Vector | AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions 9 through 9.2.4
Description
The issue is related to insufficient validation of administrator-provided data in the Image URL Import Feature, allowing a rogue administrator to inject malicious code when importing images. This leads to the execution of the malicious code on the website user's browser. A rogue administrator could exploit this to inject malicious code.
Recommendations
For Concrete CMS versions 9 through 9.2.4, update to version 9.2.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the Image URL Import Feature to minimize the risk of exploitation. Avoid using the Image URL Import Feature until the issue is resolved.
Fix
XSS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Concrete Cms