Impact
Concrete CMS versions below 9.5.3 do not sanitize custom style values entered in the Block Design dialog. When an editor writes these values into page CSS, the values are inserted into a DOM sink unescaped, allowing an attacker to store malicious script code. An editor-level user can execute the script in an administrator’s session, effectively escalating privileges. The weakness is a classic Stored Cross‑Site Scripting flaw, classified as CWE‑79.
Affected Systems
The affected product is Concrete CMS by Concrete CMS. All releases prior. The issue does not affect versions 9.5.3 and newer.
Risk and Exploitability
The CVSS score of 7.0 indicates high severity. The base vector shows a network attack surface with low attack complexity, requiring authenticated user privileges (editor level). Because the vulnerability is stored and does not demand direct input from the attacker at the time of execution, it can remain hidden until an editor injects the malicious value. There is no publicly known active exploitation; the EPSS score is < 1%, and the vulnerability is not listed in the KEV catalog.
OpenCVE Enrichment