PT-2025-13636 · Unknown · Concrete Cms

Published

2025-03-30

·

Updated

2025-03-31

·

CVE-2025-2964

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ConcreteCMS versions up to 9.3.9
Description A problematic issue was found in the function Save of the component FAQ Block Handler. The manipulation of the argument Navigation/Title Text/Description Source leads to cross-site scripting. It is possible to launch the attack remotely. The issue has been disclosed to the public.
Recommendations For versions up to 9.3.9, consider disabling the Save function of the FAQ Block Handler component until a patch is available. Restrict access to the FAQ Block Handler to minimize the risk of exploitation. Avoid using the Navigation/Title Text/Description Source argument in the affected component until the issue is resolved.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2964

Affected Products

Concrete Cms