PT-2026-91752 · Unknown · Concrete Cms
CVSS v4.0
7.3
High
| Vector | AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions prior to 9.5.3
Description
Stored cross-site scripting occurs because the YouTube block only applies the
trim() function to stored width and height values. These values are then printed into iframe HTML attributes without escaping or integer casting. A user with edit block permission can inject an event handler that executes scripts for visitors viewing the page. If the visitor has administrative privileges, the script executes with those privileges.Recommendations
Update Concrete CMS to version 9.5.3 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms