CyberRota Analysis
AI-GeneratedConcrete CMS versions prior to 9.5.3 are susceptible to a Stored XSS vulnerability through the Date Format field in the Page Attribute Display block, allowing users with edit_page_contents permissions to inject malicious scripts. This could lead to the execution of the payload in the browsers of any visitors viewing the affected pages, potentially compromising user data and session integrity. Organizations using Concrete CMS should prioritize patching this vulnerability to mitigate risks associated with unauthorized script execution.
Original NVD Description
Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. A user with edit_page_contents permissions could store a payload which executes in the browser of any visitor who viewed a page where the block was configured to display a date-type attribute. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 4.8 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Oriol Ortiz for reporting.