Concrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search Field. Prior to the fix, stored XSS could be executed by an administrator changing a filter to which a rogue administrator had previously added malicious code. The Concrete CMS security team gave this vulnerability a CVSS v3.1 score of 3.1 with a vector of AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator . Thanks Alexey Solovyev for reporting
History

Mon, 16 Dec 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Vendors & Products Concretecms
Concretecms concrete Cms

Fri, 30 Aug 2024 22:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Fri, 30 Aug 2024 21:30:00 +0000

Type Values Removed Values Added
Description Concrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search Field. Prior to the fix, stored XSS could be executed by an administrator changing a filter to which a rogue administrator had previously added malicious code. The Concrete CMS security team gave this vulnerability a CVSS v3.1 score of 3.1 with a vector of AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator . Thanks Alexey Solovyev for reporting Concrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search Field. Prior to the fix, stored XSS could be executed by an administrator changing a filter to which a rogue administrator had previously added malicious code. The Concrete CMS security team gave this vulnerability a CVSS v3.1 score of 3.1 with a vector of AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator . Thanks Alexey Solovyev for reporting
Weaknesses CWE-79

cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published: 2024-04-03T19:09:44.345Z

Updated: 2024-08-30T21:17:27.290Z

Reserved: 2024-04-02T06:07:37.812Z

Link: CVE-2024-3181

cve-icon Vulnrichment

Updated: 2024-08-01T20:05:07.637Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-03T20:15:07.077

Modified: 2024-12-16T19:07:04.087

Link: CVE-2024-3181

cve-icon Redhat

No data.