Impact
Concrete CMS versions below 9.5.3 fail to encode user‑defined form question labels when rendering the dashboard form submissions report. A rogue editor can insert arbitrary HTML or JavaScript into a label. When any administrator opens the report for that form, the web browser executes the stored markup as part of the dashboard page, giving the attacker the ability to run arbitrary scripts with the administrative session session hijacking, credential theft, or lateral movement within the site. The weakness falls under CWE‑79: Improper Neutralization of Input During Web Page Generation.
Affected Systems
All installations of Concrete CMS labeled as Concrete CMS with a version earlier than 9.5.3. No specific minor versions are listed, but any deployment running a pre‑9.5.3 release is vulnerable.
Risk and Exploitability
The CVSS score of 8.4 classifies this as a high‑severity vulnerability. EPSS data is currently unavailable, and the vulnerability is not yet in the CISA KEV catalog. The likely attack requires an attacker who can create or edit a form block to a role normally held by an editor or administrator. Once the malicious label is stored, any subsequent admin who opens the form submission report becomes the target. Because the vulnerability is stored, there is no need for network‑level access; simply being able to submit or edit a form label suffices to set up the payload.
OpenCVE Enrichment