VDB
Sign up
MEDIUM4.8

GHSA-998c-q8hh-h8gv

Concrete CMS stored XSS vulnerability in the "Top Navigator Bar" block

Quick fix

GHSA-998c-q8hh-h8gv — concrete5/concrete5: upgrade to the fixed version with the command below.

composer require concrete5/concrete5:^9.3.3

Details

Concrete CMS versions 9.0.0 through 9.3.3 are affected by a stored XSS vulnerability in the "Top Navigator Bar" block. Since the "Top Navigator Bar" output was not sufficiently sanitized, a rogue administrator could add a malicious payload that could be executed when targeted users visited the home page. This does not affect versions below 9.0.0 since they do not have the Top Navigator Bar Block. Thanks, Chu Quoc Khanh for reporting.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/concrete5/concrete5
Introduced in: 9.0.0Fixed in: 9.3.3
Fixcomposer require concrete5/concrete5:^9.3.3

References