CVE-2024-7398

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Sep 25, 2024
Updated: Jan 21, 2025
CWE ID 79

Summary

CVE-2024-7398 is a stored Cross-Site Scripting (XSS) vulnerability affecting Concrete CMS versions 9 through 9.3.3 and older versions below 8.5.19. The flaw lies in the calendar event addition feature, where the event name is not properly sanitized before output. Malicious users with permissions to create or modify calendar events can embed harmful scripts, potentially leading to code execution. The Concrete CMS Security Team assessed this issue with a CVSS v4 score of 4.6, classifying it as a Medium severity risk. Access privileges were initially considered in the risk assessment but were later lowered based on CVSS 4.0 documentation. Yusuke Uchida discovered this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Concretecms Concrete Cms
  • Concrete CMS

Affected Vendors

  • Concrete CMS