PT-2024-17599 · Unknown · Concrete Cms

·

CVE-2024-1245

·

Published

2024-02-09

·

Updated

2024-02-15

CVSS v3.1

2.4

Low

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Concrete CMS version 9 before 9.2.5
Description The issue concerns stored XSS in file tags and description attributes. Administrator-entered file attributes are not sufficiently sanitized in the Edit Attributes page, allowing a rogue administrator to put malicious code into the file tags or description attributes. This malicious code could execute when another administrator opens the same file for editing.
Recommendations For Concrete CMS version 9 before 9.2.5, update to version 9.2.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the Edit Attributes page to minimize the risk of exploitation. Additionally, avoid using unsanitized input from administrator-entered file attributes in the file tags or description attributes until the issue is resolved.

Exploit

Fix

DoS

RCE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-1245
GHSA-MGP6-J658-VCW9

Affected Products

Concrete Cms