Moderate severityNVD Advisory· Published Dec 25, 2023· Updated Aug 2, 2024
CVE-2023-48650
CVE-2023-48650
Description
Concrete CMS before 8.5.14 and 9 before 9.2.3 is vulnerable to an admin adding a stored XSS payload via the Layout Preset name.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
concrete5/concrete5Packagist | < 8.5.14 | 8.5.14 |
concrete5/concrete5Packagist | >= 9.0.0, < 9.2.3 | 9.2.3 |
Affected products
1Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-x577-gcc9-9xjjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-48650ghsaADVISORY
- documentation.concretecms.org/developers/introduction/version-history/923-release-notesghsaWEB
- github.com/concretecms/concretecms/commit/077755e6bbbc1c67b7508add9e3d207e8d8909a0ghsaWEB
- github.com/concretecms/concretecms/commit/5b93470bcccf271810d3a0b190368ce6a9d6c84bghsaWEB
- www.concretecms.org/about/project-news/security/2023-12-05-concrete-cms-new-cves-and-cve-updatesghsaWEB
News mentions
0No linked articles in our index yet.