Concrete CMS versions 9.0.0 through 9.3.3 are affected by a
stored XSS vulnerability in the "Top Navigator Bar" block.
Since the "Top Navigator Bar" output was not sufficiently sanitized, a rogue administrator could add a malicious payload that could be executed when targeted users visited the home page.The Concrete CMS Security Team gave this vulnerability a CVSS v4 score of 4.6
with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N . This
does not affect versions below 9.0.0 since they do not have the Top
Navigator Bar Block. Thanks, Chu Quoc Khanh for reporting.
Metrics
Affected Vendors & Products
References
History
Mon, 23 Sep 2024 23:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Concretecms
Concretecms concrete Cms |
|
CPEs | cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:* | |
Vendors & Products |
Concretecms
Concretecms concrete Cms |
|
Metrics |
cvssV3_1
|
Wed, 18 Sep 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 17 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Concrete CMS versions 9.0.0 through 9.3.3 are affected by a stored XSS vulnerability in the "Top Navigator Bar" block. Since the "Top Navigator Bar" output was not sufficiently sanitized, a rogue administrator could add a malicious payload that could be executed when targeted users visited the home page.The Concrete CMS Security Team gave this vulnerability a CVSS v4 score of 4.6 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N . This does not affect versions below 9.0.0 since they do not have the Top Navigator Bar Block. Thanks, Chu Quoc Khanh for reporting. | |
Title | Stored XSS in the "Top Navigator Bar" block | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: ConcreteCMS
Published: 2024-09-17T18:13:59.210Z
Updated: 2024-09-18T14:26:21.912Z
Reserved: 2024-09-10T16:23:36.368Z
Link: CVE-2024-8660
Vulnrichment
Updated: 2024-09-18T14:26:16.993Z
NVD
Status : Analyzed
Published: 2024-09-17T19:15:28.953
Modified: 2024-09-23T23:00:00.437
Link: CVE-2024-8660
Redhat
No data.