CVE-2023-44766: XSS
Published Oct 6, 2023
·Updated
A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a crafted script to the SEO - Extra from Page Settings.
Affected Software
2 affected components
composer/concrete5/concrete5<=9.2.1
ConcreteCMS Concrete CMS=9.2.1
Event History
Oct 6, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Advisory Published
03:30 PM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-44766.
2
What is the severity of CVE-2023-44766?
The severity of CVE-2023-44766 is medium with a CVSS score of 5.4.
3
How does the Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 impact the system?
The XSS vulnerability allows an attacker to execute arbitrary code by injecting a crafted script to the SEO - Extra from Page Settings.
4
Which versions of Concrete CMS are affected by CVE-2023-44766?
Concrete CMS v.9.2.1 is affected by CVE-2023-44766.
5
How can I fix the Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1?
To fix the XSS vulnerability, update Concrete CMS to a version that has a patch for the vulnerability.