PT-2026-42563 · Unknown · Concrete Cms
Yonatan Drori
·
Published
2026-05-21
·
Updated
2026-05-22
·
CVE-2026-8245
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions prior to 9.5.1
Description
Reflected Cross-Site Scripting (XSS) occurs in Legacy Pagination through HTML attribute injection. The
ConcreteCoreLegacyPagination class constructs pagination links by raw-interpolating the $URL variable into the href attribute of an anchor tag. An authenticated administrator or report viewer with access to the '/dashboard/reports/forms/legacy' endpoint can trigger the payload in their session by clicking a crafted URL.Recommendations
Update to a version newer than 9.5.0.
Restrict access to the '/dashboard/reports/forms/legacy' endpoint to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms