Impact
Concrete CMS versions prior to 9.5.4 allow an unauthenticated user to upload plain XML documents via a public Form Block file‑upload question. The system validates uploads only by file extension and serves them inline with the application’s origin. An attacker can embed an XML‑STYLESHEET instruction that points to a malicious XSLT resource on the same domain. When a victim opens the stored file, the browser applies the stylesheet, rendering attacker‑controlled JavaScript in the Concrete CMS context. If the victim is an authenticated administrator, the script runs with administrative privileges and can, for example, create new Administrator accounts. This is a stored XSS flaw that can compromise confidentiality, integrity, and availability for privileged users.
Affected Systems
Concrete CMS, all versions older than 9.5.4
Risk and Exploitability
The CVSS v4.0 score of 7.3 indicates moderate to high severity. The EPSS score of less than 1 % suggests low probability of widespread exploitation, and the vulnerability is not listed in CISA KEV. The attack does not require network privileges, relies on an unauthenticated upload to a publicly exposed Form Block, and then requires a victim to open the stored XML file in a browser. The flaw can be exploited by anyone with access to the Form Block, and malicious scripts will execute under the victim’s session.
OpenCVE Enrichment