MEDIUM4.8
GHSA-8699-h45g-7hm8
Concrete CMS Cross-site Scripting vulnerability
Quick fix
GHSA-8699-h45g-7hm8 — concrete5/concrete5: upgrade to the fixed version with the command below.
composer require concrete5/concrete5:^8.5.10Details
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting (XSS) in dashboard/system/express/entities/associations because Concrete CMS allows association with an entity name that doesn’t exist or, if it does exist, contains XSS since it was not properly sanitized. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/concrete5/concrete5
Introduced in:
0Fixed in: 8.5.10Fix
composer require concrete5/concrete5:^8.5.10Packagist/concrete5/concrete5
Introduced in:
9.0.0Fixed in: 9.1.3Fix
composer require concrete5/concrete5:^9.1.3References
- https://nvd.nist.gov/vuln/detail/CVE-2022-43695[ADVISORY]
- https://documentation.concretecms.org/developers/introduction/version-history/8510-release-notes[WEB]
- https://documentation.concretecms.org/developers/introduction/version-history/913-release-notes[WEB]
- https://github.com/concretecms[PACKAGE]
- https://github.com/concretecms/concretecms/releases/8.5.10[WEB]
- https://github.com/concretecms/concretecms/releases/9.1.3[WEB]
- https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2022-10-31[WEB]