Impact
Concrete CMS versions earlier than 9.5.4 allow the user timezone value to be stored without validation and later rendered without output encoding on the dashboard user‑management page. A stored cross‑site scripting payload placed in this field executes on a dashboard view, allowing an attacker to run arbitrary JavaScript within an administrator’s session. This could be used to exfiltrate session tokens, create new administrator accounts, or alter site settings, thereby compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability applies to Concrete CMS deployments below 9.5.4. In version 9.5.3 the dangerous timezone field can be accessed by unauthenticated users if public registration is enabled; in earlier releases any authenticated user can reach the same field via the account profile editor. Exploitation requires the concrete.misc.user_timezones feature to be enabled, which is disabled by default, and optionally public registration enabled for the unauthenticated path.
Risk and Exploitability
The Common Vulnerability Scoring System assigns a 7.7 score, indicating high severity, while the Exploit Prediction Scoring System shows a probability of less than 1%, reflecting a low likelihood of active exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to create a malicious input in the timezone field, which then runs when an administrator views the affected user, so the path involves leveraging the stored XSS in an administrative session rather than a remote network exploit.
OpenCVE Enrichment