Impact
Concrete CMS versions file description and tags fields in the Document Library block without applying HTML escaping, allowing an editor to persist malicious script payloads in the database. When a page containing the block is viewed, the unescaped content is injected into the page’s HTML and executed in the visitor’s browser. This vulnerability can be used to steal session tokens or perform actions on behalf of the victim, thereby compromising confidentiality and integrity for anyone who accesses the affected block. The weakness is a classic Stored XSS, classified as CWE‑79.
Affected Systems
All installations running Concrete CMS earlier than 9.5.3 are affected. The issue resides in the core Document Library block component, and any page displaying that block with the description or tags columns enabled exposes the risk. Users with edit permissions on file properties can inject the payload; unauthenticated visitors can be impacted if they view pages that include the vulnerable block.
Risk and Exploitability
The CVSS v4.0 score of 5.1 indicates a moderate severity. The attack vector is network‑public, but an attacker must first have edit rights to file properties. The EPSS score of < 1% suggests a very low likelihood of exploitation in the editor role and simply uploads the malicious content; once stored, the payload is served to all visitors, including unauthenticated users.
OpenCVE Enrichment