CVE Database
/

CVE-2022-43556

Back to search

CVE-2022-43556

Published: Dec 5, 2022

Modified: Apr 24, 2025

PUBLISHED

Description

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XSS in the text input field since the result dashboard page output is not sanitized. The Concrete CMS security team has ranked this 4.2 with CVSS v3.1 vector AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N Thanks @_akbar_jafarli_ for reporting. Remediate by updating to Concrete CMS 8.5.10 and Concrete CMS 9.1.3.

VendorProductVersions

n/a

https://github.com/concretecms/concretecms

affected
Fixed in Concrete CMS 8.5.10 and Concrete CMS 9.1.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now