MEDIUM
GHSA-45fj-fvmm-xcc5
Concrete CMS has a stored Cross-site Scripting (XSS) vulnerability
Quick fix
GHSA-45fj-fvmm-xcc5 — concrete5/concrete5: upgrade to the fixed version with the command below.
composer require concrete5/concrete5:^9.4.8Details
In Concrete CMS below version 9.4.8, a user with permission to edit a page with element Legacy form can perform a stored XSS attack towards high-privilege accounts via the Question field.
The Concrete CMS security team thanks minhnn42, namdi and quanlna2 from VCSLab-Viettel Cyber Security for reporting.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/concrete5/concrete5
Introduced in:
0Fixed in: 9.4.8Fix
composer require concrete5/concrete5:^9.4.8