VulnerabilityModified
CVE-2023-28820
Concrete CMS (previously concrete5) before 9.1 is vulnerable to stored XSS in RSS Displayer via the href attribute because the link element input was not sanitized.
MEDIUM 5.4EPSS 0.39%
Does this matter?
Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.
Description
Concrete CMS (previously concrete5) before 9.1 is vulnerable to stored XSS in RSS Displayer via the href attribute because the link element input was not sanitized.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.39% probability · 33th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- concretecms/concrete cms
- Source
- cve@mitre.org
References
- https://github.com/concretecms/concretecms/releasesRelease Notes
- https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2023-04-20Vendor Advisory
- https://github.com/concretecms/concretecms/releasesRelease Notes
- https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2023-04-20Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.