CVE-2022-43556: XSS
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XSS in the text input field since the result dashboard page output is not sanitized. The Concrete CMS security team has ranked this 4.2 with CVSS v3.1 vector AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N Thanks @akbarjafarli for reporting. Remediate by updating to Concrete CMS 8.5.10 and Concrete CMS 9.1.3.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-43556.
What is the severity of CVE-2022-43556?
The severity of CVE-2022-43556 is medium.
What is the Common Weakness Enumeration (CWE) for CVE-2022-43556?
The Common Weakness Enumeration (CWE) for CVE-2022-43556 is CWE-79.
How can I fix CVE-2022-43556?
To fix CVE-2022-43556, update Concrete CMS to version 8.5.10 or above, or upgrade to version 9.1.2 or above.
Where can I find more information about CVE-2022-43556?
More information about CVE-2022-43556 can be found in the following references: [link1], [link2], [link3].