MEDIUM4.8
GHSA-998c-q8hh-h8gv
Concrete CMS stored XSS vulnerability in the "Top Navigator Bar" block
Quick fix
GHSA-998c-q8hh-h8gv — concrete5/concrete5: upgrade to the fixed version with the command below.
composer require concrete5/concrete5:^9.3.3Details
Concrete CMS versions 9.0.0 through 9.3.3 are affected by a stored XSS vulnerability in the "Top Navigator Bar" block. Since the "Top Navigator Bar" output was not sufficiently sanitized, a rogue administrator could add a malicious payload that could be executed when targeted users visited the home page. This does not affect versions below 9.0.0 since they do not have the Top Navigator Bar Block. Thanks, Chu Quoc Khanh for reporting.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/concrete5/concrete5
Introduced in:
9.0.0Fixed in: 9.3.3Fix
composer require concrete5/concrete5:^9.3.3References
- https://nvd.nist.gov/vuln/detail/CVE-2024-8660[ADVISORY]
- https://github.com/concretecms/concretecms/pull/12128[WEB]
- https://github.com/concretecms/concretecms/commit/f5a01c88fb2630db96e58dcd7f52ea41e516d4e9[WEB]
- https://documentation.concretecms.org/9-x/developers/introduction/version-history/934-release-notes[WEB]
- https://github.com/concretecms/concretecms[PACKAGE]