Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Surajbhosale

#28934of 57,623
9.6Total CVSS
Vulnerabilities · 1
PT-2026-93846
9.6
2026-09-16
Concrete Cms · Concrete Cms · CVE-2026-85385
**Name of the Vulnerable Software and Affected Versions** Concrete CMS versions prior to 9.5.4 **Description** Stored cross-site scripting occurs because the software fails to validate the `uTimezone` value during write operations and renders it without output encoding on the Dashboard user management page. This happens when the `Date::getTimezoneDisplayName()` function returns any non-IANA value unchanged. An attacker can save a malicious payload in this field, which then executes in an administrator's browser session when the affected user is viewed. This could allow the attacker to read CSRF tokens, create administrator accounts, or modify site settings. In version 9.5.3, this field is accessible to unauthenticated visitors via public registration, while in versions prior to 9.5.3, it is accessible to any authenticated user through the account profile editor. Exploitation requires the `concrete.misc.user timezones` setting to be enabled, and the unauthenticated path further requires public registration to be enabled. **Recommendations** Update Concrete CMS to version 9.5.4 or later. Disable the `concrete.misc.user timezones` setting to prevent exploitation. Disable public registration to mitigate the risk for unauthenticated access.