ZeroHour

CVE-2023-28477

CVSS 3.1
5.4 medium
EPSS
<1%p46
Published
()
Modified
Description

Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to stored XSS on API Integrations via the name parameter.

Vendors
concretecms
Products
concrete cms
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.