Impact
Concrete CMS before version 9.5.3 contains a stored cross‑site scripting flaw that is triggered when SVG files are uploaded with the "Reject" sanitization mode enabled. In that mode the system checks only a limited blocklist that rejects the <script> element and on* event‑handler attributes, while discarding the more comprehensive sanitization pass that would normally strip dangerous content such as javascript: URIs in an xlink:href attribute. As a result, a malicious SVG containing executable JavaScript can be stored on the server and will run automatically when any user opens the file, allowing an attacker to run arbitrary code in the victim’s browser.
Affected Systems
The vulnerability affects Concrete CMS releases prior to 9.5.3 when the configuration parameter concrete.file_manager.images.svg_sanitization.action is set to "reject". The default sanitization mode is not impacted, and the flaw only applies if the reject mode is explicitly chosen. Users who have permission to upload SVG files are at risk until the patch or configuration change is applied.
Risk and Exploitability
The CVSS v4.0 score of 1.8 indicates low severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation in practice. The flaw requires that an attacker can upload SVG files in an environment where the reject mode is active, which limits the attack surface to users with upload privileges. Because the vulnerability is not listed in the CISA KEV catalog, the threat is confined to browser execution in users who view the malicious file and does not result in broader system compromise.
OpenCVE Enrichment