MEDIUM5.4
GHSA-7388-7vq2-m4f4
Concrete CMS Cross-site Scripting via Survey Blocks
Quick fix
GHSA-7388-7vq2-m4f4 — concrete5/concrete5: upgrade to the fixed version with the command below.
composer require concrete5/concrete5:^8.5.5Details
Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct Cross-site Scripting (XSS) attacks via a crafted survey block. This requires at least Editor privileges.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/concrete5/concrete5
Introduced in:
0Fixed in: 8.5.5Fix
composer require concrete5/concrete5:^8.5.5