CVE-2024-1247

Improper Input Validation in packagist/concrete5/concrete5

Identifiers

GHSA-q25h-jch8-gfrp, CVE-2024-1247

Package Slug

packagist/concrete5/concrete5

Vulnerability

Improper Input Validation

Description

Concrete CMS version 9 before 9.2.5 is vulnerable to  stored XSS via the Role Name field since there is insufficient validation of administrator provided data for that field. A rogue administrator could inject malicious code into the Role Name field which might be executed when users visit the affected page. The Concrete CMS Security team scored this 2 with CVSS v3 vector AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator . Concrete versions below 9 do not include group types so they are not affected by this vulnerability.

Affected Versions

All versions starting from 9.0.0rc1 before 9.2.5

Solution

Upgrade to version 9.2.5 or above.

Last Modified

2024-02-12

source