MEDIUM5.4
GHSA-6xx7-r8x4-fpjp
ConcreteCMS Cross-site Scripting vulnerability
Quick fix
GHSA-6xx7-r8x4-fpjp — concrete5/concrete5: upgrade to the fixed version with the command below.
composer require concrete5/concrete5:^9.2.2Details
A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a crafted script to Plural Handle of the Data Objects from System & Settings.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/concrete5/concrete5
Introduced in:
0Fixed in: 9.2.2Fix
composer require concrete5/concrete5:^9.2.2References
- https://nvd.nist.gov/vuln/detail/CVE-2023-44765[ADVISORY]
- https://github.com/concretecms/concretecms/pull/11746[WEB]
- https://github.com/concretecms/concretecms/pull/11746/commits/0f0564232e0a49719d0bdff6223539b624f116ee[WEB]
- https://github.com/concretecms/concretecms/pull/11746/commits/92bcc208078571f4beda38cb0952f8e99887737a[WEB]
- https://github.com/concretecms/concretecms[PACKAGE]
- https://github.com/sromanhu/ConcreteCMS-Stored-XSS---Associations[WEB]
- https://www.concretecms.org/about/project-news/security/2023-11-09-security-blog-about-updated-cves-and-new-release[WEB]