Description
Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output encoding on the Dashboard user management page, where Date::getTimezoneDisplayName() returns any non-IANA value unchanged. A stored cross-site scripting payload saved in this field executed in an administrator's browser when they viewed the affected user in the Dashboard, running script in the admin session (for example to read CSRF tokens, create administrator accounts, or change site settings). In Concrete CMS 9.5.3 the field became reachable by unauthenticated visitors through public registration; in Concrete CMS below 9.5.3, the same field was reachable by any authenticated user through the account profile editor. Exploitation required concrete.misc.user_timezones to be enabled (off by default), and the unauthenticated path additionally required public registration to be enabled. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.7 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Suraj Bhosale for reporting.
Published: 2026-09-16
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting that can execute in an administrator’s browser
Action: Apply patch
AI Analysis

Impact

Concrete CMS versions earlier than 9.5.4 allow the user timezone value to be stored without validation and later rendered without output encoding on the dashboard user‑management page. A stored cross‑site scripting payload placed in this field executes on a dashboard view, allowing an attacker to run arbitrary JavaScript within an administrator’s session. This could be used to exfiltrate session tokens, create new administrator accounts, or alter site settings, thereby compromising confidentiality, integrity, and availability.

Affected Systems

The vulnerability applies to Concrete CMS deployments below 9.5.4. In version 9.5.3 the dangerous timezone field can be accessed by unauthenticated users if public registration is enabled; in earlier releases any authenticated user can reach the same field via the account profile editor. Exploitation requires the concrete.misc.user_timezones feature to be enabled, which is disabled by default, and optionally public registration enabled for the unauthenticated path.

Risk and Exploitability

The Common Vulnerability Scoring System assigns a 7.7 score, indicating high severity, while the Exploit Prediction Scoring System shows a probability of less than 1%, reflecting a low likelihood of active exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to create a malicious input in the timezone field, which then runs when an administrator views the affected user, so the path involves leveraging the stored XSS in an administrative session rather than a remote network exploit.

Generated by OpenCVE AI on September 18, 2026 at 01:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.4 or later, where input validation and output encoding have been added for the timezone field.
  • If upgrading is not immediately possible, disable the concrete.misc.user_timezones feature in the configuration to prevent the field from accepting arbitrary data.
  • Additionally, disable public registration or restrict it to trusted accounts to eliminate the unauthenticated attack vector.
  • Remove any existing malicious data from user timezone fields to eliminate already stored payloads.

Generated by OpenCVE AI on September 18, 2026 at 01:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Fri, 18 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output encoding on the Dashboard user management page, where Date::getTimezoneDisplayName() returns any non-IANA value unchanged. A stored cross-site scripting payload saved in this field executed in an administrator's browser when they viewed the affected user in the Dashboard, running script in the admin session (for example to read CSRF tokens, create administrator accounts, or change site settings). In Concrete CMS 9.5.3 the field became reachable by unauthenticated visitors through public registration; in Concrete CMS below 9.5.3, the same field was reachable by any authenticated user through the account profile editor. Exploitation required concrete.misc.user_timezones to be enabled (off by default), and the unauthenticated path additionally required public registration to be enabled. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.7 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Suraj Bhosale for reporting.
Title Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-17T17:34:54.284Z

Reserved: 2026-09-03T18:09:30.566Z

Link: CVE-2026-85385

cve-icon Vulnrichment

Updated: 2026-09-17T17:34:51.157Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T17:18:15.577

Modified: 2026-09-21T17:52:41.260

Link: CVE-2026-85385

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:15:02Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')