Impact
The flaw occurs when a calendar event name is stored without sanitization and later displayed in workflow approval or deletion notifications without HTML escaping. Because these notifications appear in the dashboard block, a registered user who can add events to a calendar governed by an approval workflow can submit a name containing a malicious script. When an administrator views the pending request, the embedded script executes in the administrator’s browser context, allowing the attacker to create a new administrator account and thus gain full control of the site. The vulnerability is thus a stored cross‑site scripting flaw that enables remote code execution within an administrator’s browser and elevation of privilege.
Affected Systems
Concrete CMS versions from 8.3.0 up to and including 9.5.2 are affected. No patched or fixed version is listed in the available data.
Risk and Exploitability
The CVSS v4.0 score of 7.3 indicates a high severity. The exploit requires the attacker to be a registered user able the notification; thus the attack is local to the administrative interface and requires user interaction. The EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV catalog, which suggests that exploitation is not currently widespread but remains possible. Given the potential for privilege escalation, the risk to systems with an active approval workflow remains significant.
OpenCVE Enrichment