CVE-2024-8291

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Sep 25, 2024
Updated: Jan 17, 2025
CWE ID 22
CWE ID 79

Summary

CVE-2024-8291: A significant vulnerability affects Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19. This Stored XSS issue, discovered by Alexey Solovyev, allows rogue admins to insert malicious code into the Image Editor Background Color. The Concrete CMS Security Team initially rated this vulnerability with a CVSS v4 score of 5.1 (Medium), considering it an Adversary Controlled (AC:H) risk. However, CNA later revised the AC to Low (AC:L) based on updated CVSS 4.0 documentation. This vulnerability can lead to potential code injection, posing a risk to site integrity and user safety.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Concretecms Concrete Cms

Affected Vendors

  • Concrete CMS