ZeroHour

CVE-2023-28475

CVSS 3.1
6.1 medium
EPSS
<1%p49
Published
()
Modified
Description

Concrete CMS (previously concrete5) versions 8.5.12 and below, and versions 9.0 through 9.1.3 is vulnerable to Reflected XSS on the Reply form because msgID was not sanitized.

Vendors
concretecms
Products
concrete cms
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.