VDB
Sign up
LOW3.0

GHSA-q5wx-m95r-4cgc

Concrete CMS Stored Cross-site Scripting vulnerability

Quick fix

GHSA-q5wx-m95r-4cgc — concrete5/concrete5: upgrade to the fixed version with the command below.

composer require concrete5/concrete5:^8.5.18

Details

Concrete CMS versions 9.0.0 to 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer when user input is stored and later embedded into responses. A rogue administrator could inject malicious code into fields due to insufficient input validation.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/concrete5/concrete5
Introduced in: 0Fixed in: 8.5.18
Fixcomposer require concrete5/concrete5:^8.5.18
Packagist/concrete5/concrete5
Introduced in: 9.0.0RC1Fixed in: 9.3.3
Fixcomposer require concrete5/concrete5:^9.3.3

References