Concrete CMS Cross-site Scripting (XSS) in the Advanced File Search Filter
Low severity
GitHub Reviewed
Published
Apr 3, 2024
to the GitHub Advisory Database
•
Updated Apr 3, 2024
Package
Affected versions
>= 9.0.0RC1, < 9.2.8
< 8.5.16
Patched versions
9.2.8
8.5.16
Description
Published by the National Vulnerability Database
Apr 3, 2024
Published to the GitHub Advisory Database
Apr 3, 2024
Reviewed
Apr 3, 2024
Last updated
Apr 3, 2024
Concrete CMS versions 9 below 9.2.8 and versions below 8.5.16 are vulnerable to Cross-site Scripting (XSS) in the Advanced File Search Filter. Prior to the fix, a rogue administrator could add malicious code in the file manager because of insufficient validation of administrator provided data. All administrators have access to the File Manager and hence could create a search filter with the malicious code attached. The Concrete CMS security team gave this vulnerability a CVSS v3.1 score of 3.1 with a vector of AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator .
References