CVE-2024-2179
- EPSS 0.31%
- Veröffentlicht 05.03.2024 21:15:09
- Zuletzt bearbeitet 16.12.2024 19:01:03
Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group type since there is insufficient validation of administrator provided data for that field. A rogue administrator could inject malicious code into the Name f...
CVE-2023-49337
- EPSS 0.55%
- Veröffentlicht 29.02.2024 01:41:37
- Zuletzt bearbeitet 16.12.2024 19:11:00
Concrete CMS before 9.2.3 allows Stored XSS on the Admin Dashboard via /dashboard/system/basics/name. (8.5 and earlier are unaffected.)
CVE-2023-48650
- EPSS 0.49%
- Veröffentlicht 29.02.2024 01:41:34
- Zuletzt bearbeitet 16.12.2024 19:12:48
Concrete CMS before 8.5.14 and 9 before 9.2.3 is vulnerable to an admin adding a stored XSS payload via the Layout Preset name.
CVE-2023-48651
- EPSS 0.28%
- Veröffentlicht 29.02.2024 01:41:34
- Zuletzt bearbeitet 16.12.2024 19:12:28
Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) at /ccm/system/dialogs/file/delete/1/submit.
CVE-2023-48653
- EPSS 0.28%
- Veröffentlicht 29.02.2024 01:41:34
- Zuletzt bearbeitet 16.12.2024 19:11:44
Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/delete/submit. An attacker can force an admin to delete events on the site because the event ID is numeric and sequential.
CVE-2024-1245
- EPSS 0.4%
- Veröffentlicht 09.02.2024 20:15:54
- Zuletzt bearbeitet 21.11.2024 08:50:08
Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes since administrator entered file attributes are not sufficiently sanitized in the Edit Attributes page. A rogue administrator could put malicious ...
CVE-2024-1246
- EPSS 0.45%
- Veröffentlicht 09.02.2024 20:15:54
- Zuletzt bearbeitet 21.11.2024 08:50:08
Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature due to insufficient validation of administrator provided data. A rogue administrator could inject malicious code when importing images, leading to ...
CVE-2024-1247
- EPSS 1.24%
- Veröffentlicht 09.02.2024 19:15:24
- Zuletzt bearbeitet 21.11.2024 08:50:09
Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS via the Role Name field since there is insufficient validation of administrator provided data for that field. A rogue administrator could inject malicious code into the Role Name field ...
CVE-2023-48652
- EPSS 0.23%
- Veröffentlicht 25.12.2023 08:15:07
- Zuletzt bearbeitet 21.11.2024 08:32:11
Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) via /ccm/system/dialogs/logs/delete_all/submit. An attacker can force an admin user to delete server report logs on a web application to which they are currently authentic...
CVE-2023-48648
- EPSS 1.23%
- Veröffentlicht 17.11.2023 04:15:07
- Zuletzt bearbeitet 21.11.2024 08:32:10
Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creation functions (such as the Mkdir() function) gives universal access (0777) to created folders by defaul...