CVE-2023-44765: XSS
A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a crafted script to Plural Handle of the Data Objects from System & Settings.
Other sources
A Cross Site Scripting (XSS) vulnerability in Concrete CMS versions 8.5.12 and below, and 9.0 through 9.2.1 allows an attacker to execute arbitrary code via a crafted script to Plural Handle of the Data Objects from System & Settings.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-44765?
CVE-2023-44765 is a Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 that allows an attacker to execute arbitrary code.
How does CVE-2023-44765 work?
CVE-2023-44765 works by leveraging a crafted script to the Plural Handle of the Data Objects from System & Settings in Concrete CMS v.9.2.1.
What is the severity of CVE-2023-44765?
CVE-2023-44765 has a severity level of medium, with a CVSS score of 5.4.
What software versions are affected by CVE-2023-44765?
Concrete CMS v.9.2.1 is affected by CVE-2023-44765.
How can I fix CVE-2023-44765?
To fix CVE-2023-44765, it is recommended to update Concrete CMS to a version that contains the necessary patches.