PT-2026-42543 · Unknown · Concrete Cms
Alfin Joseph
·
Published
2026-05-21
·
Updated
2026-05-21
·
CVE-2026-8203
CVSS v4.0
7.3
High
| Vector | AV:N/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions 9.5.0 and earlier
Description
A stored cross-site scripting (XSS) issue exists because the controller fails to validate or sanitize the
height parameter. This allows users with editor privileges to inject malicious JavaScript that executes in the browser of any visitor, which could lead to credential theft or session hijacking.Recommendations
Update to a version later than 9.5.0.
As a temporary workaround, restrict editor privileges to trusted users to minimize the risk of malicious script injection via the
height parameter.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms