PT-2024-24203 · Unknown · Concrete Cms
Guram
+1
·
Published
2024-04-03
·
Updated
2024-12-16
·
CVE-2024-3178
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions 9 below 9.2.8 and versions below 8.5.16
Description
The issue concerns Cross-site Scripting (XSS) in the Advanced File Search Filter. A rogue administrator could add malicious code in the file manager due to insufficient validation of administrator-provided data. All administrators have access to the File Manager and could create a search filter with the malicious code attached.
Recommendations
For versions 9 below 9.2.8 and versions below 8.5.16, update to version 9.2.8 or 8.5.16 or later to resolve the issue. As a temporary workaround, consider restricting access to the Advanced File Search Filter in the File Manager to minimize the risk of exploitation.
Fix
XSS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Concrete Cms