Impact
Concrete CMS versions below 9.5.3 fail to encode user‑defined form question labels when rendering the dashboard form submissions report. A rogue editor can insert arbitrary HTML or JavaScript into a label. When any administrator opens the report for that form, the web browser executes the stored markup as part of the dashboard page, giving the attacker the ability to run arbitrary scripts with the administrative session, potentially leading to credential theft, session hijacking, or lateral movement within the site. The weakness falls under CWE‑79: Improper Neutralization of Input During Web Page Generation.
Affected Systems
All installations of Concrete CMS labeled as Concrete CMS with a version earlier than 9.5.3. Any deployment running a pre‑9.5.3 release is vulnerable.
Risk and Exploitability
The CVSS score of 8.4 classifies this as a high‑severity vulnerability. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack requires an attacker who can create or edit a form block with an editor or administrator role. Once the malicious label is stored, any subsequent administrator who opens the form submission report becomes the target, as the stored payload is executed in the administrator's browser without any network‑level access.
OpenCVE Enrichment