Impact
This vulnerability allows a user who can edit page content to store malicious JavaScript in the Date Format field of the Page Attribute Display block. This is a Stored Cross‑Site Scripting flaw (CWE‑79). When a visitor views a page where the block is configured to display a date‑type attribute, the script executes in the visitor’s browser. The impact is client‑side code execution within the visitor’s browser, exposing them to potential damage limited to what the injected script can perform.
Affected Systems
Concrete CMS installations running any version earlier than 9.5.3 are affected. The issue is confined to the Page Attribute Display block and the date‑format configuration within that block.
Risk and Exploitability
The CVSS score is 4.8. The exploit requires the attacker to have edit_page_contents permissions, which are typically held by site editors or administrators. The vector AV:N indicates the attack can be performed over the network. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, implying no widespread, actively used exploit is known. Nevertheless, any user with edit_page_contents permissions can compromise all visitors to affected pages.
OpenCVE Enrichment