CVE-2024-7398
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-7398 is a stored Cross-Site Scripting (XSS) vulnerability affecting Concrete CMS versions 9 through 9.3.3 and older versions below 8.5.19. The flaw lies in the calendar event addition feature, where the event name is not properly sanitized before output. Malicious users with permissions to create or modify calendar events can embed harmful scripts, potentially leading to code execution. The Concrete CMS Security Team assessed this issue with a CVSS v4 score of 4.6, classifying it as a Medium severity risk. Access privileges were initially considered in the risk assessment but were later lowered based on CVSS 4.0 documentation. Yusuke Uchida discovered this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Concretecms Concrete Cms
- Concrete CMS
Affected Vendors
- Concrete CMS