CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-4353: Stored XSS in Generate Board Name Input Field

4.6 CVSS

Description

Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in the generate dashboard board
instance functionality. The Name input field does not check the input sufficiently letting a rogue administrator have the capability to inject malicious
JavaScript code. The Concrete CMS security team gave this vulnerability a CVSS v4 score of 4.6 with a vector of CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Concrete versions below 9 are not affected by this vulnerability.Thanks fhAnso for reporting. (CNA updated this risk rank on 17 Jan 2025 by lowering the AC based on CVSS 4.0 documentation that access privileges should not be considered for AC).

Classification

CVE ID: CVE-2024-4353

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.6

Affected Products

Vendor: Concrete CMS

Product: Concrete CMS

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 16.42% (scored less or equal to compared to others)

EPSS Date: 2025-02-15 (when was this score calculated)

References

https://github.com/concretecms/concretecms/pull/12151
https://documentation.concretecms.org/9-x/developers/introduction/version-history/933-release-notes

Timeline