CVE-2024-8291
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Summary
CVE-2024-8291: A significant vulnerability affects Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19. This Stored XSS issue, discovered by Alexey Solovyev, allows rogue admins to insert malicious code into the Image Editor Background Color. The Concrete CMS Security Team initially rated this vulnerability with a CVSS v4 score of 5.1 (Medium), considering it an Adversary Controlled (AC:H) risk. However, CNA later revised the AC to Low (AC:L) based on updated CVSS 4.0 documentation. This vulnerability can lead to potential code injection, posing a risk to site integrity and user safety.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Concretecms Concrete Cms
Affected Vendors
- Concrete CMS