CVE-2024-2179

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 5, 2024
Updated: Dec 16, 2024
CWE ID 200
CWE ID 89

Summary

CVE-2024-2179 is a newly disclosed vulnerability affecting Concrete CMS version 9 before 9.2.7. This issue stems from insufficient validation of administrator-supplied data in the Name field of a Group type. A malicious administrator can exploit this flaw to inject malicious code, posing a potential risk for users visiting the affected page. The Concrete CMS security team assessed this vulnerability with a moderate CVSS v3.1 score of 2.2 (AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N). Concrete CMS versions below 9, which do not include group types, are not susceptible to this vulnerability. Luca Fuda reported this security issue to the Concrete CMS team.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share