PT-2024-39159 · Unknown · Concrete Cms

Chu Quoc Khanh

·

Published

2024-09-16

·

Updated

2024-12-16

·

CVE-2024-8661

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Concrete CMS versions 9.0.0 through 9.3.4 Concrete CMS versions below 8.5.19
Description: A Stored XSS vulnerability exists in the "Next&Previous Nav" block of Concrete CMS, allowing a rogue administrator to add a malicious payload that can be executed in the browsers of targeted users. This is due to insufficient sanitization of the block's output.
Recommendations: For Concrete CMS versions 9.0.0 through 9.3.4, update to a version that includes the fix for this issue. For Concrete CMS versions below 8.5.19, update to a version that includes the fix for this issue. As a temporary workaround, consider disabling the "Next&Previous Nav" block until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-8661
GHSA-XMXJ-V2Q8-8QX6

Affected Products

Concrete Cms