ZeroHour

CVE-2023-48649

CVSS 3.1
5.4 medium
EPSS
<1%p46
Published
()
Modified
Description

Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows stored XSS on the Admin page via an uploaded file name.

Vendors
concretecms
Products
concrete cms
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.