VDB
Sign up
LOW2.0

GHSA-c47w-9mcf-w972

Concrete CMS vulnerable to Stored Cross-site Scripting

Quick fix

GHSA-c47w-9mcf-w972 — concrete5/concrete5: upgrade to the fixed version with the command below.

composer require concrete5/concrete5:^9.3.3

Details

Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in Board instances. A rogue administrator could inject malicious code.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/concrete5/concrete5
Introduced in: 9.0.0RC1Fixed in: 9.3.3
Fixcomposer require concrete5/concrete5:^9.3.3

References