An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS05OThjLXE4aGgtaDhnds4AA_nA

Moderate CVSS: 4.6 EPSS: 0.00229% (0.45488 Percentile) EPSS:

Concrete CMS stored XSS vulnerability in the "Top Navigator Bar" block

Affected Packages Affected Versions Fixed Versions
packagist:concrete5/concrete5 >= 9.0.0, < 9.3.3 9.3.3
4 Dependent packages
7 Dependent repositories
2,415 Downloads total

Affected Version Ranges

All affected versions

9.0.0, 9.0.0RC1, 9.0.0RC3, 9.0.0RC4, 9.0.1, 9.0.2, 9.1.0, 9.1.1, 9.1.2, 9.1.3, 9.2.0, 9.2.0RC2, 9.2.1, 9.2.2, 9.2.3, 9.2.4, 9.2.5, 9.2.6, 9.2.7, 9.2.8, 9.2.9, 9.3.0, 9.3.1, 9.3.2

All unaffected versions

8.0.1, 8.0.2, 8.0.3, 8.1.0, 8.2.0, 8.2.0RC2, 8.2.1, 8.3.0, 8.3.1, 8.3.2, 8.4.0, 8.4.0RC3, 8.4.0RC4, 8.4.1, 8.4.2, 8.4.3, 8.4.4, 8.4.5, 8.5.0, 8.5.0RC1, 8.5.0RC2, 8.5.1, 8.5.2, 8.5.3, 8.5.4, 8.5.5, 8.5.6, 8.5.6RC1, 8.5.7, 8.5.8, 8.5.9, 8.5.10, 8.5.11, 8.5.12, 8.5.13, 8.5.14, 8.5.15, 8.5.16, 8.5.17, 8.5.18, 8.5.19, 8.5.20, 8.5.21, 8.5.99, 9.3.3, 9.3.4, 9.3.5, 9.3.6, 9.3.7, 9.3.8, 9.3.9, 9.4.0, 9.4.0RC1, 9.4.0RC2, 9.4.1, 9.4.2, 9.4.3, 9.4.4, 9.4.5, 9.4.6, 9.4.7

Concrete CMS versions 9.0.0 through 9.3.3 are affected by a stored XSS vulnerability in the "Top Navigator Bar" block. Since the "Top Navigator Bar" output was not sufficiently sanitized, a rogue administrator could add a malicious payload that could be executed when targeted users visited the home page. This does not affect versions below 9.0.0 since they do not have the Top
Navigator Bar Block. Thanks, Chu Quoc Khanh for reporting.

References: