Impact
Concrete CMS versions 9.5.2 and earlier sanitize the YouTube block’s width and height fields only with trim(), then insert those values directly into iframe attributes without escaping or numeric casting. An attacker who can edit a block can insert an inline event handler that will be rendered in the iframe and executed in the browsers of any visitor. Because the code runs whenever the page is rendered, a victim who is an administrator can be compromised, enabling credential theft or further exploitation. This flaw is a stored cross‑site scripting vulnerability and exemplifies CWE‑79.
Affected Systems
Any Concrete CMS deployment prior to version 9.5.3 that continues to use the legacy YouTube block is affected, regardless of custom extensions that rely on the block.
Risk and Exploitability
The CVSS v4.0 score of 7.3 indicates high severity. Exploitation requires only edit_block permission, a role that may be widely available in many environmentsISA very low exploitation probability, with a score of 0.00251 (0.25%). Yet the remote and authorized block‑editing attack path suggests that risk could be significant in organizations where block‑editing permissions are not tightly controlled. Prompt patching or restriction of edit privileges reduces the attack surface.
OpenCVE Enrichment