PT-2026-91747 · Unknown · Concrete Cms
CVSS v4.0
7.3
High
| Vector | AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions 8.3.0 through 9.5.2
Description
Stored calendar event names are saved without sanitization and rendered without HTML escaping in the workflow approval and deletion notifications within the dashboard "Waiting For Me" block. A registered user with permissions to add events to a calendar governed by an approval workflow can submit an event name containing a script payload. This payload executes in an administrator's browser when the pending request is displayed, potentially allowing the creation of a new administrator account.
Recommendations
Update Concrete CMS to a version later than 9.5.2.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms