CVE-2024-1247 LOW

CVE-2024-1247: Concrete CMS version 9 before 9.2.5 vulnerable to stored XSS via the Role Name field

Vendor Concrete Cms
Product Concrete CMS
Weakness CWE-20 · Input validation
Published February 9, 2024
Last update August 1, 2024

CVSS base score

2.0/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Concrete CMS version 9 before 9.2.5 is vulnerable to  stored XSS via the Role Name field since there is insufficient validation of administrator provided data for that field. A rogue administrator could inject malicious code into the Role Name field which might be executed when users visit the affected page. The Concrete CMS Security team scored this 2 with CVSS v3 vector AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator . Concrete versions below 9 do not include group types so they are not affected by this vulnerability.

Key dates

02Disclosure timeline

February 9, 2024 CVE published
August 1, 2024 Record updated