PT-2026-93846 · Concrete Cms+1 · Concrete Cms
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions prior to 9.5.4
Description
Stored cross-site scripting occurs because the software fails to validate the
uTimezone value during write operations and renders it without output encoding on the Dashboard user management page. This happens when the Date::getTimezoneDisplayName() function returns any non-IANA value unchanged. An attacker can save a malicious payload in this field, which then executes in an administrator's browser session when the affected user is viewed. This could allow the attacker to read CSRF tokens, create administrator accounts, or modify site settings. In version 9.5.3, this field is accessible to unauthenticated visitors via public registration, while in versions prior to 9.5.3, it is accessible to any authenticated user through the account profile editor. Exploitation requires the concrete.misc.user timezones setting to be enabled, and the unauthenticated path further requires public registration to be enabled.Recommendations
Update Concrete CMS to version 9.5.4 or later.
Disable the
concrete.misc.user timezones setting to prevent exploitation.
Disable public registration to mitigate the risk for unauthenticated access.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms