Impact
Concrete CMS versions before 9.5.3 contain a stored Cross‑Site Scripting vulnerability that arises when an Address attribute is submitted without a country. The country‑less formatter bypasses HTML‑escaping, and one or more Express association templates echo the association label mask without sanitisation. This allows attacker to inject arbitrary JavaScript, which then runs in the browser context of any dashboard user who opens the affected entry. The impact is the potential theft of session or execution of further malicious actions on behalf of the victim.
Affected Systems
All installations of Concrete CMS running a version earlier than 9.5.3 are vulnerable. The flaw resides in Express association views, such as concrete/elements/express/form/view/dashboard/association.php, where the absence of a country field allows unescaped content to be rendered directly into the page.
Risk and Exploitability
The CVSS v4.0 score of 7.5 indicates high severity with distant network access, low complexity, and user interaction. The EPSS score of less than 1% indicates low analysis. The vulnerability is not listed in the CISA KEV catalog. Attackers are likely to exploit the flaw by submitting a contrived Address attribute through a public or authenticated form; once stored, the malicious script executes whenever a dashboard user views the entry, enabling credential theft, session hijacking, or defacement.
OpenCVE Enrichment