Impact
Concrete CMS versions 9.0.0 through 9.5.2 accept a Page Container icon value without validation and later embed it directly into an img tag’s src attribute. Because the output helper does not encode the attribute, a crafted value can break out of the src context and inject arbitrary script that runs in the authenticated context of another editor or administrator. This allows an attacker to steal session tokens and perform privileged dashboard actions while logged in.
Affected Systems
All sites running Concrete CMS between versions 9.0.0 and 9.5.2 are affected, including any deployment that has not applied a later release. Users with delegated access to the Page Containers dashboard are the ones who can introduce the malicious icon value.
Risk and Exploitability
The CVSS score of 7.0 indicates moderate to high severity. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not in the CISA KEV catalog. The exploit requires an authenticated attack with delegated dashboard permissions, so the attack surface is limited to users who can edit page containers. Nevertheless, once a malicious icon is stored, any subsequent dashboard view by an editor or administrator will execute the injected script, providing a foothold for session hijacking or further privilege escalation.
OpenCVE Enrichment