Medium severity4.8NVD Advisory· Published Aug 8, 2024· Updated Jun 17, 2026
CVE-2024-7394
CVE-2024-7394
Description
Concrete CMS versions 9 through 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in getAttributeSetName(). A rogue administrator could inject malicious code. The Concrete CMS team gave this a CVSS v4.0 rank of 4.6 with vector https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks, m3dium for reporting. (CNA updated this risk rank on 20 Jan 2025 by lowering the AC based on CVSS 4.0 documentation that access privileges should not be considered for AC)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
concrete5/concrete5Packagist | < 8.5.18 | 8.5.18 |
concrete5/concrete5Packagist | >= 9.0.0, < 9.3.3 | 9.3.3 |
Affected products
3- Range: 9
Patches
Vulnerability mechanics
References
8- github.com/concretecms/concretecms/commit/c08d9671cec4e7afdabb547339c4bc0bed8eab06nvdPatchWEB
- github.com/concretecms/concretecms/pull/12166nvdIssue TrackingPatchWEB
- documentation.concretecms.org/9-x/developers/introduction/version-history/933-release-notesnvdRelease NotesVendor AdvisoryWEB
- documentation.concretecms.org/developers/introduction/version-history/8518-release-notesnvdRelease NotesVendor AdvisoryWEB
- github.com/advisories/GHSA-w6j6-w6jx-vf2rghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-7394ghsaADVISORY
- github.com/concretecms/concretecms/commit/3a5974e94892c43388c3529e57a140bf2967c734ghsaWEB
- github.com/concretecms/concretecms/commit/e7e0eb95a0c4d0875c3712e33f495be76578cd5aghsaWEB
News mentions
0No linked articles in our index yet.