First published: Fri Oct 01 2021(Updated: )
Cross-site scripting (XSS) vulnerability in concrete/elements/collection_theme.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the rel parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Concrete5 | <=5.6.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41465 is considered a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2021-41465, upgrade your concrete5-legacy installation to version 5.6.4.1 or later.
Exploitation of CVE-2021-41465 allows attackers to inject arbitrary web scripts or HTML, potentially compromising user data or leading to further attacks.
CVE-2021-41465 affects users of concrete5-legacy version 5.6.4.0 and below.
CVE-2021-41465 specifically targets the concrete/elements/collection_theme.php component in affected versions of concrete5-legacy.