CVE-2024-2179
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-2179 is a newly disclosed vulnerability affecting Concrete CMS version 9 before 9.2.7. This issue stems from insufficient validation of administrator-supplied data in the Name field of a Group type. A malicious administrator can exploit this flaw to inject malicious code, posing a potential risk for users visiting the affected page. The Concrete CMS security team assessed this vulnerability with a moderate CVSS v3.1 score of 2.2 (AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N). Concrete CMS versions below 9, which do not include group types, are not susceptible to this vulnerability. Luca Fuda reported this security issue to the Concrete CMS team.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- F5 Networks