Low severity3.1NVD Advisory· Published Apr 3, 2024· Updated Jun 17, 2026
CVE-2024-3181
CVE-2024-3181
Description
Concrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search Field. Prior to the fix, stored XSS could be executed by an administrator changing a filter to which a rogue administrator had previously added malicious code. The Concrete CMS security team gave this vulnerability a CVSS v3.1 score of 3.1 with a vector of AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator . Thanks Alexey Solovyev for reporting
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
concrete5/concrete5Packagist | >= 9.0.0RC1, < 9.2.8 | 9.2.8 |
concrete5/concrete5Packagist | < 8.5.16 | 8.5.16 |
Affected products
3- Range: 9.0.0
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-qgm9-rxmq-jxmqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-3181ghsaADVISORY
- documentation.concretecms.org/9-x/developers/introduction/version-history/928-release-notesnvdRelease NotesWEB
- documentation.concretecms.org/developers/introduction/version-history/8516-release-notesnvdRelease NotesWEB
- github.com/concretecms/concretecms/commit/822e689cefe1eb876e9de31dad9ce660f3b5c295ghsaWEB
- github.com/concretecms/concretecms/commit/e85ef2408a5eea7d5646178fbef0ab243baaed8fghsaWEB
News mentions
0No linked articles in our index yet.