PT-2023-21989 · Unknown · Concrete Cms

CVE-2023-28820

·

Published

2023-04-28

·

Updated

2025-01-31

CVSS v3.1

2.0

Low

VectorAC:H/AV:N/A:N/C:L/I:N/PR:H/S:U/UI:R
Name of the Vulnerable Software and Affected Versions Concrete CMS (previously concrete5) versions prior to 9.1
Description The issue concerns stored XSS in the RSS Displayer via the href attribute. This occurs because the link element input was not sanitized, allowing for potential exploitation.
Recommendations For versions prior to 9.1, update to version 9.1 or later to resolve the issue. As a temporary workaround, consider disabling the RSS Displayer feature until a patch is available. Restrict access to the RSS Displayer module to minimize the risk of exploitation. Avoid using the href attribute in the RSS Displayer until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-28820
GHSA-FGXJ-G7X3-85CQ

Affected Products

Concrete Cms