PT-2025-13639 · Unknown · Concrete Cms
Published
2025-03-30
·
Updated
2025-03-31
·
CVE-2025-2967
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ConcreteCMS versions up to 9.3.9
Description
A vulnerability was found in ConcreteCMS, affecting the
Save function of the HTML Block Handler component. The manipulation of the content argument leads to HTML injection. This issue can be initiated remotely.Recommendations
For versions up to 9.3.9, update to a version later than 9.3.9 to resolve the issue.
As a temporary workaround, consider restricting the use of the
Save function in the HTML Block Handler component until a patch is available.
Avoid using the content argument in the affected component to minimize the risk of exploitation.Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Concrete Cms