Impact
Concrete CMS versions 9.0.0 through 9.5.2 contain a stored cross‑site scripting vulnerability in the Board Custom Slot save_template endpoint. The endpoint only verifies that the requester can edit the target board (canEditBoardContents()) and then stores the client‑supplied selectedTemplateOption[collection] data directly, without re‑constructing the content or confirming that the items belong to the board’s data pool. Because the default summary template renders the description field without output encoding, an attacker who can edit a board can insert a malicious summary whose description contains JavaScript‑bearing HTML. When that board slot is viewed, the payload executes in the browser of any user who sees the board, including anonymous front‑end visitors and logged‑in dashboard users, potentially enabling session hijacking or higher‑privilege activity.
Affected Systems
The affected product is Concrete CMS, specifically versions 9.0.0 to 9.5.2. Earlier Concrete CMS releases prior to 9.0 do not include the Boards feature and are not affected.
Risk and Exploitability
The flaw carries a CVSS v4.0 score of 5.8, reflecting moderate severity, while its EPSS score is below 1%, indicating a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. A successful exploit requires the attacker to have edit permissions on at least one board, after which the stored XSS can affect any visitor of the board slot, providing an opportunity for session or action takeover and possible escalation to administrative credentials.
OpenCVE Enrichment