LOW
GHSA-q9fm-mpg8-8jqm
Concrete CMS is vulnerable to Stored XSS via page name in the Atomik theme
Quick fix
GHSA-q9fm-mpg8-8jqm — concrete5/concrete5: upgrade to the fixed version with the command below.
composer require concrete5/concrete5:^9.5.1Details
Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript that executes in the context of any authenticated user visiting the affected account pages. This can lead to session hijacking, credential theft, malicious actions performed on behalf of users, and potential privilege escalation. Thanks Yonatan Drori (Tenzai) for reporting.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/concrete5/concrete5
Introduced in:
9.0.0RC.1Fixed in: 9.5.1Fix
composer require concrete5/concrete5:^9.5.1