CVE-2024-4350
Description
Concrete CMS versions 9.0.0 to 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer when user input is stored and later embedded into responses. A rogue administrator could inject malicious code into fields due to insufficient input validation. The Concrete CMS security team gave this vulnerability a CVSS v4 score of 5.1 with vector https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Thanks, m3dium for reporting. (CNA updated this risk rank on 17 Jan 2025 by lowering the AC based on CVSS 4.0 documentation that access privileges should not be considered for AC)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
concrete5/concrete5Packagist | < 8.5.18 | 8.5.18 |
concrete5/concrete5Packagist | >= 9.0.0RC1, < 9.3.3 | 9.3.3 |
Affected products
3- Range: 9.0.0
Patches
Vulnerability mechanics
References
7- github.com/concretecms/concretecms/commit/c08d9671cec4e7afdabb547339c4bc0bed8eab06nvdPatchWEB
- github.com/concretecms/concretecms/pull/12166nvdPatchWEB
- documentation.concretecms.org/9-x/developers/introduction/version-history/933-release-notesnvdRelease NotesVendor AdvisoryWEB
- documentation.concretecms.org/developers/introduction/version-history/8518-release-notesnvdRelease NotesVendor AdvisoryWEB
- github.com/advisories/GHSA-q5wx-m95r-4cgcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-4350ghsaADVISORY
- github.com/concretecms/concretecms/commit/55e485e06b0b3342613a55af6a7c61d939d2ccb5ghsaWEB
News mentions
0No linked articles in our index yet.