Impact
Concrete CMS versions 9.0.0 through 9.5.3 do not neutralize custom page alias names. The Edit Alias dialog accepts the raw input after only trimming whitespace, so an authenticated user with canWrite permission can store an alias containing malicious script content. When an admin or editor later opens the Sitemap panel, the unsanitized alias is rendered unescaped in the page title area and the embedded script executes automatically, allowing the user to elevate privileges within the victim’s active session. The weakness is a classic input validation failure that results in stored cross‑site scripting.
Affected Systems
All installations of Concrete CMS that include the affected version range, namely 9.0.0 through 9.5.3. Any site where page administrators can edit alias names and grant canWrite rights to editors is vulnerable.
Risk and Exploitability
The CVSS v4.0 score of 7.3 indicates a high severity vulnerability. The EPSS score of less than 1% points to a low overall exploitation probability across the population, yet the vulnerability can be activated by any authenticated editor who can adjust a page alias, making it likely to be exploited in environments where such permissions are common. Though it is not listed in the CISA KEV catalog, this stored XSS can lead to privilege escalation to administrator within the victim’s active session.
OpenCVE Enrichment