PT-2026-92180 · Unknown · Concrete Cms
CVSS v4.0
7.5
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions prior to 9.5.3
Description
Stored Cross-Site Scripting (XSS) is possible in Express association views due to the Address attribute's country-less text formatter skipping HTML-escaping. This occurs when a non-required Address attribute accepts a blank country and specific Express association templates, such as
concrete/elements/express/form/view/dashboard/association.php, echo the association label mask without applying the h() function. A user capable of submitting an Address attribute can execute arbitrary scripts in the session of any dashboard user who views the affected entry.Recommendations
Update to version 9.5.3 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms