MEDIUM5.4
GHSA-p4jj-gwpg-9jwh
ConcreteCMS Cross-site Scripting vulnerability
Quick fix
GHSA-p4jj-gwpg-9jwh — concrete5/concrete5: upgrade to the fixed version with the command below.
composer require concrete5/concrete5:^9.2.2Details
Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS v.9.2.1 allow a local attacker to execute arbitrary code via a crafted script to the Forms of the Data objects.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/concrete5/concrete5
Introduced in:
0Fixed in: 9.2.2Fix
composer require concrete5/concrete5:^9.2.2