Impact
Concrete CMS versions 9.0 to 9.5.2 are vulnerable because the Top Navigation Bar block does not HTML‑escape dropdown child page names before rendering them. A user who can create or rename pages can insert JavaScript into a child page name, which is then stored and executed in the browsers of any visitor, editor, or administrator who views the navigation. The injected script runs with the privileges of the viewer and can read same‑origin content or perform any actions available to that user, creating a high‑impact compromise.
Affected Systems
The affected product is Concrete CMS, specifically versions 9.0 through 9.5.2 where the Top Navigation Bar block is present. Users of these releases should verify whether their installations use this block.
Risk and Exploitability
The CVSS v4.0 score for this flaw is 7.5, indicating a high severity. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw via persistent malicious input on page names, a vector that requires the attacker to have rights to create or rename pages. If such access is available, the stored script can be triggered simply by a visitor browsing the affected navigation bar.
OpenCVE Enrichment