sromanhu/CVE-2023-44761_ConcreteCMS-Stored-XSS---Forms

sromanhu/CVE-2023-44761_ConcreteCMS-Stored-XSS---Forms

Releases0
Cross Site Scripting vulnerability in ConcreteCMS v.9.2.1 allows a local attacker to execute arbitrary code via a crafted script to the Form of the Data Objects.

CVE History

CVEPublishedCVSS v3CVSS v2
5.4 MEDIUM

Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 through 9.2.1 allow a local attacker to execute arbitrary code via a crafted script to the Forms of the Data objects.