Impact
Based on the description, Concrete CMS 9.4.0 through 9.5.2 fails to escape page paths submitted through the duplicate‑path confirmation dialog, returning the raw path in a JSON response that client‑side JavaScript injects as raw HTML. This flaw enables an attacker to inject malicious script that executes within the editor’s authenticated browser context, leading to cross‑site scripting. The weakness is an instance of improper input validation, identified as CWE‑79.
Affected Systems
Concrete CMS versions 9.4.0 through 9.5.2 are affected. The issue originates in the location panel’s duplicate‑path confirmation dialog used by the editor component. Users with editor access who can create or modify page paths are the only ones attacking paths that can trigger the vulnerability.
Risk and Exploitability
The CVSS v4.0 score of 2.0 indicates a low severity, and the EPSS score of less than 1% suggests exploitation is unlikely in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is client‑side through the browser; an attacker must have an authenticated editor session and craft a malicious page path to trigger the execution. Because the attack impacts only the privileges of the authenticated user, the overall risk remains modest but should not be ignored.
OpenCVE Enrichment