MEDIUM5.4
GHSA-9h33-5fxw-r2xv
Stored cross site scripting via container name
Quick fix
GHSA-9h33-5fxw-r2xv — concrete5/concrete5: upgrade to the fixed version with the command below.
composer require concrete5/concrete5:^9.2.0Details
Concrete CMS (previously concrete5) before 9.2 is vulnerable to Stored XSS via a container name.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/concrete5/concrete5
Introduced in:
0Fixed in: 9.2.0Fix
composer require concrete5/concrete5:^9.2.0References
- https://nvd.nist.gov/vuln/detail/CVE-2023-28471[ADVISORY]
- https://concretecms.com[WEB]
- https://github.com/concretecms/concretecms[PACKAGE]
- https://www.concretecms.org/about/project-news/security/2023-12-05-concrete-cms-new-cves-and-cve-updates[WEB]
- https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2023-04-20[WEB]