CVE-2023-48650

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Feb 29, 2024
Updated: Dec 16, 2024
CWE ID 79

Summary

CVE-2023-48650 is a newly disclosed vulnerability affecting Concrete CMS versions 8.5.13 and earlier, as well as 9.x before 9.2.3. An attacker can exploit this issue by convincingly manipulating the Layout Preset name during the admin panel, allowing for the injection of a stored Cross-Site Scripting (XSS) payload. This threat can potentially compromise user sessions and steal sensitive data, underscoring the importance of updating impacted systems promptly.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Concretecms Concrete Cms

Affected Vendors

  • Concrete CMS