Impact
Concrete CMS versions prior to 9.5.3 fail to neutralize a user‑supplied custom date format when rendering conversation messages, creating a reflected cross‑site scripting flaw that aligns with CWE‑79. The vulnerability allows malicious code execution in a victim’s browser after the user submits a crafted POST request to the conversation view endpoint, potentially compromising client‑side confidentiality, integrity, and availability for that user.
Affected Systems
Vendor: Concrete CMS. Product: Concrete CMS. Vulnerable editions include any releases before 9.5.3; any instance of Concrete CMS running those versions is at risk.
Risk and Exploitability
The CVSS v4.0 score of 2.1 indicates low overall severity, and the EPSS score of less than 1% shows a very low probability of exploitation in the wild. However, the vulnerability’s exploitation is aided by the lack of a CSRF token on the endpoint, enabling an attacker to deliver a payload via an auto‑submitting cross‑origin POST without authentication. The flaw is exposed on a publicly accessible endpoint, meaning that exploitation does not require prior authentication or privileged access, increasing the potential risk for exposed installations. The flaw is not listed in the CISA KEV catalog.
OpenCVE Enrichment