No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8855 | A vulnerability, which was classified as problematic, has been found in ConcreteCMS up to 9.3.9. This issue affects the function addEditQuestion of the component Legacy Form Block Handler. The manipulation of the argument Question leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. |
No reference.
Thu, 03 Apr 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 CWE-94 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Thu, 03 Apr 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | ConcreteCMS Legacy Form Block addEditQuestion cross site scripting | |
| Metrics |
ssvc
|
Thu, 03 Apr 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability, which was classified as problematic, has been found in ConcreteCMS up to 9.3.9. This issue affects the function addEditQuestion of the component Legacy Form Block Handler. The manipulation of the argument Question leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| Metrics |
cvssV3_0
|
cvssV4_0
|
Mon, 31 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 30 Mar 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability, which was classified as problematic, has been found in ConcreteCMS up to 9.3.9. This issue affects the function addEditQuestion of the component Legacy Form Block Handler. The manipulation of the argument Question leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | ConcreteCMS Legacy Form Block addEditQuestion cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Subscriptions
No data.
Status: REJECTED
Assigner: VulDB
Published:
Updated: 2025-04-03T22:43:13.507Z
Reserved: 2025-03-30T07:15:43.578Z
Link: CVE-2025-2963
Updated:
Status : Rejected
Published: 2025-03-30T22:15:15.597
Modified: 2025-04-03T23:15:38.103
Link: CVE-2025-2963
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD