Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type file. Stored XSS could be caused by a rogue administrator adding malicious code to the link-text field when creating a block of type file. The Concrete CMS security team gave this vulnerability a CVSS v3.1 score of 3.1 with a vector of AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator . Thanks Alexey Solovyev for reporting.
Metrics
Affected Vendors & Products
References
History
Mon, 16 Dec 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Concretecms
Concretecms concrete Cms |
|
CPEs | cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:* | |
Vendors & Products |
Concretecms
Concretecms concrete Cms |
Fri, 30 Aug 2024 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-20 |
Fri, 30 Aug 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 |
Thu, 08 Aug 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type file. Prior to fix, stored XSS could be caused by a rogue administrator adding malicious code to the link-text field when creating a block of type file. The Concrete CMS security team gave this vulnerability a CVSS v3.1 score of 3.1 with a vector of AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator . Thanks Alexey Solovyev for reporting. | Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type file. Stored XSS could be caused by a rogue administrator adding malicious code to the link-text field when creating a block of type file. The Concrete CMS security team gave this vulnerability a CVSS v3.1 score of 3.1 with a vector of AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator . Thanks Alexey Solovyev for reporting. |
MITRE
Status: PUBLISHED
Assigner: ConcreteCMS
Published: 2024-04-03T19:00:02.642Z
Updated: 2024-08-30T21:18:06.229Z
Reserved: 2024-04-02T05:51:00.964Z
Link: CVE-2024-3180
Vulnrichment
Updated: 2024-08-01T20:05:08.222Z
NVD
Status : Analyzed
Published: 2024-04-03T19:15:44.560
Modified: 2024-12-16T19:04:13.787
Link: CVE-2024-3180
Redhat
No data.