VDB
Sign up
LOW3.1

GHSA-9qhc-pg6j-wf23

Concrete CMS Stored XSS in blocks of type file

Quick fix

GHSA-9qhc-pg6j-wf23 — concrete5/concrete5: upgrade to the fixed version with the command below.

composer require concrete5/concrete5:^9.2.8

Details

Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type file. Stored XSS could be caused by a rogue administrator adding malicious code to the link-text field when creating a block of type file. The Concrete CMS security team gave this vulnerability a CVSS v3.1 score of 3.1 with a vector of AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator . Thanks Alexey Solovyev for reporting.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/concrete5/concrete5
Introduced in: 9.0.0RC1Fixed in: 9.2.8
Fixcomposer require concrete5/concrete5:^9.2.8
Packagist/concrete5/concrete5
Introduced in: 0Fixed in: 8.5.16
Fixcomposer require concrete5/concrete5:^8.5.16

References