Unrated severityNVD Advisory· Published Jan 5, 2015· Updated May 6, 2026
CVE-2014-9526
CVE-2014-9526
Description
Multiple cross-site scripting (XSS) vulnerabilities in concrete5 5.7.2.1, 5.7.2, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gName parameter in single_pages/dashboard/users/groups/bulkupdate.php or (2) instance_id parameter in tools/dashboard/sitemap_drag_request.php.
Affected products
2- cpe:2.3:a:concretecms:concrete_cms:5.7.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- morxploit.com/morxploits/morxconxss.txtnvdExploit
- packetstormsecurity.com/files/129446/Concrete5-CMS-5.7.2-5.7.2.1-Cross-Site-Scripting.htmlnvdExploit
- seclists.org/fulldisclosure/2014/Dec/38nvdExploit
- www.securityfocus.com/archive/1/534189/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/99264nvd
News mentions
0No linked articles in our index yet.