PT-2024-24203 · Unknown · Concrete Cms

·

CVE-2024-3178

·

Published

2024-04-03

·

Updated

2024-12-16

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Concrete CMS versions 9 below 9.2.8 and versions below 8.5.16
Description The issue concerns Cross-site Scripting (XSS) in the Advanced File Search Filter. A rogue administrator could add malicious code in the file manager due to insufficient validation of administrator-provided data. All administrators have access to the File Manager and could create a search filter with the malicious code attached.
Recommendations For versions 9 below 9.2.8 and versions below 8.5.16, update to version 9.2.8 or 8.5.16 or later to resolve the issue. As a temporary workaround, consider restricting access to the Advanced File Search Filter in the File Manager to minimize the risk of exploitation.

Exploit

Fix

RCE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-3178
GHSA-XWRH-QXMC-X8C8

Affected Products

Concrete Cms