Concretecms

Concrete Cms

119 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Veröffentlicht 03.04.2024 19:15:44
  • Zuletzt bearbeitet 16.12.2024 19:03:45

Concrete CMS version 9 before 9.2.8 and previous versions before 8.5.16 are vulnerable to Stored XSS in the Custom Class page editing. Prior to the fix, a rogue administrator could insert malicious code in the custom class field due to insufficient v...

  • EPSS 0.1%
  • Veröffentlicht 03.04.2024 19:15:44
  • Zuletzt bearbeitet 16.12.2024 19:04:13

Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type file. Stored XSS could be caused by a rogue administrator adding malicious code to the link-text field when creating a block of type f...

  • EPSS 0.25%
  • Veröffentlicht 03.04.2024 19:15:43
  • Zuletzt bearbeitet 16.12.2024 19:01:58

Concrete CMS version 9 before 9.2.8 and previous versions prior to 8.5.16 is vulnerable to Stored XSS on the calendar color settings screen since Information input by the user is output without escaping. A rogue administrator could inject malicious j...

  • EPSS 0.12%
  • Veröffentlicht 05.03.2024 21:15:09
  • Zuletzt bearbeitet 16.12.2024 19:01:03

Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group type since there is insufficient validation of administrator provided data for that field. A rogue administrator could inject malicious code into the Name f...

  • EPSS 0.46%
  • Veröffentlicht 29.02.2024 01:41:37
  • Zuletzt bearbeitet 16.12.2024 19:11:00

Concrete CMS before 9.2.3 allows Stored XSS on the Admin Dashboard via /dashboard/system/basics/name. (8.5 and earlier are unaffected.)

  • EPSS 1.07%
  • Veröffentlicht 29.02.2024 01:41:34
  • Zuletzt bearbeitet 16.12.2024 19:12:48

Concrete CMS before 8.5.14 and 9 before 9.2.3 is vulnerable to an admin adding a stored XSS payload via the Layout Preset name.

  • EPSS 0.84%
  • Veröffentlicht 29.02.2024 01:41:34
  • Zuletzt bearbeitet 16.12.2024 19:12:28

Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) at /ccm/system/dialogs/file/delete/1/submit.

  • EPSS 0.84%
  • Veröffentlicht 29.02.2024 01:41:34
  • Zuletzt bearbeitet 16.12.2024 19:11:44

Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/delete/submit. An attacker can force an admin to delete events on the site because the event ID is numeric and sequential.

  • EPSS 0.55%
  • Veröffentlicht 09.02.2024 20:15:54
  • Zuletzt bearbeitet 21.11.2024 08:50:08

Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes since administrator entered file attributes are not sufficiently sanitized in the Edit Attributes page. A rogue administrator could put malicious ...

  • EPSS 0.43%
  • Veröffentlicht 09.02.2024 20:15:54
  • Zuletzt bearbeitet 21.11.2024 08:50:08

Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature due to insufficient validation of administrator provided data. A rogue administrator could inject malicious code when importing images, leading to ...