LOW
GHSA-pcrh-gj77-j4mw
Concrete CMS is vulnerable to Stored XSS via external-link page cvName
Details
Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExternal bypasses being sanitized.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist / concrete5/concrete5
Introduced in:
0 Fixed in: 9.5.1 Fix
composer require concrete5/concrete5:^9.5.1