ZeroHour

CVE-2023-28476

CVSS 3.1
5.4 medium
EPSS
<1%p44
Published
()
Modified
Description

Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Tags on uploaded files.

Vendors
concretecms
Products
concrete cms
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.