CVE-2022-43695: XSS
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting (XSS) in dashboard/system/express/entities/associations because Concrete CMS allows association with an entity name that doesn’t exist or, if it does exist, contains XSS since it was not properly sanitized. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/concrete5/concrete5to a version that resolves this vulnerability.Fixed in 9.1.3 - Upgrade
Upgrade
composer/concrete5/concrete5to a version that resolves this vulnerability.Fixed in 8.5.10 - Upgrade
Upgrade
Concrete CMSto a version that resolves this vulnerability.Fixed in 9.1.3 - Upgrade
Upgrade
Concrete CMSto a version that resolves this vulnerability.Fixed in 8.5.10
Event History
Frequently Asked Questions
What is CVE-2022-43695?
CVE-2022-43695 is a vulnerability in Concrete CMS (formerly concrete5) versions below 8.5.10 and between 9.0.0 and 9.1.2 that allows for Stored Cross-Site Scripting (XSS).
How severe is CVE-2022-43695?
CVE-2022-43695 has a severity rating of 4.8, which is considered medium.
How is Concrete CMS affected by CVE-2022-43695?
Concrete CMS versions below 8.5.10 and between 9.0.0 and 9.1.2 are affected by CVE-2022-43695.
How can I fix CVE-2022-43695?
To fix CVE-2022-43695, update Concrete CMS to version 8.5.10 or higher if you are using version 8, and update to version 9.1.3 or higher if you are using version 9.
Where can I find more information about CVE-2022-43695?
You can find more information about CVE-2022-43695 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-43695) and [Concrete CMS documentation](https://documentation.concretecms.org/developers/introduction/version-history/8510-release-notes) (for version 8.5.10) and [Concrete CMS documentation](https://documentation.concretecms.org/developers/introduction/version-history/913-release-notes) (for version 9.1.3).