CVE-2024-3179
- EPSS 0.1%
- Veröffentlicht 03.04.2024 19:15:44
- Zuletzt bearbeitet 16.12.2024 19:03:45
Concrete CMS version 9 before 9.2.8 and previous versions before 8.5.16 are vulnerable to Stored XSS in the Custom Class page editing. Prior to the fix, a rogue administrator could insert malicious code in the custom class field due to insufficient v...
CVE-2024-3180
- EPSS 0.1%
- Veröffentlicht 03.04.2024 19:15:44
- Zuletzt bearbeitet 16.12.2024 19:04:13
Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type file. Stored XSS could be caused by a rogue administrator adding malicious code to the link-text field when creating a block of type f...
CVE-2024-2753
- EPSS 0.25%
- Veröffentlicht 03.04.2024 19:15:43
- Zuletzt bearbeitet 16.12.2024 19:01:58
Concrete CMS version 9 before 9.2.8 and previous versions prior to 8.5.16 is vulnerable to Stored XSS on the calendar color settings screen since Information input by the user is output without escaping. A rogue administrator could inject malicious j...
CVE-2024-2179
- EPSS 0.12%
- Veröffentlicht 05.03.2024 21:15:09
- Zuletzt bearbeitet 16.12.2024 19:01:03
Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group type since there is insufficient validation of administrator provided data for that field. A rogue administrator could inject malicious code into the Name f...
CVE-2023-49337
- EPSS 0.46%
- Veröffentlicht 29.02.2024 01:41:37
- Zuletzt bearbeitet 16.12.2024 19:11:00
Concrete CMS before 9.2.3 allows Stored XSS on the Admin Dashboard via /dashboard/system/basics/name. (8.5 and earlier are unaffected.)
CVE-2023-48650
- EPSS 1.07%
- Veröffentlicht 29.02.2024 01:41:34
- Zuletzt bearbeitet 16.12.2024 19:12:48
Concrete CMS before 8.5.14 and 9 before 9.2.3 is vulnerable to an admin adding a stored XSS payload via the Layout Preset name.
CVE-2023-48651
- EPSS 0.84%
- Veröffentlicht 29.02.2024 01:41:34
- Zuletzt bearbeitet 16.12.2024 19:12:28
Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) at /ccm/system/dialogs/file/delete/1/submit.
CVE-2023-48653
- EPSS 0.84%
- Veröffentlicht 29.02.2024 01:41:34
- Zuletzt bearbeitet 16.12.2024 19:11:44
Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/delete/submit. An attacker can force an admin to delete events on the site because the event ID is numeric and sequential.
CVE-2024-1245
- EPSS 0.55%
- Veröffentlicht 09.02.2024 20:15:54
- Zuletzt bearbeitet 21.11.2024 08:50:08
Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes since administrator entered file attributes are not sufficiently sanitized in the Edit Attributes page. A rogue administrator could put malicious ...
CVE-2024-1246
- EPSS 0.43%
- Veröffentlicht 09.02.2024 20:15:54
- Zuletzt bearbeitet 21.11.2024 08:50:08
Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature due to insufficient validation of administrator provided data. A rogue administrator could inject malicious code when importing images, leading to ...