PT-2026-93847 · Concrete Cms+1 · Concrete Cms
CVSS v4.0
7.3
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions prior to 9.5.4
Description
Insufficient sanitization of XML and XSLT documents uploaded via a public Form Block file-upload question allows an unauthenticated visitor to store a malicious XML document. Because plain XML uploads are validated only by file extension and served inline from the application origin, an attacker can include an
xml-stylesheet processing instruction referencing a same-origin XSLT stylesheet. When a victim opens the file, the browser executes attacker-controlled JavaScript in the application origin, resulting in stored cross-site scripting (XSS). If the victim is an authenticated administrator, this can lead to unauthorized actions, such as the creation of new administrative users.Recommendations
Update to version 9.5.4 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms