CVE-2023-48649: XSS
Published Nov 17, 2023
·Updated
Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows stored XSS on the Admin page via an uploaded file name.
Affected Software
4 affected componentsFixes available
composer/concrete5/concrete5>=9.0.0<9.2.2
9.2.2
composer/concrete5/concrete5<8.5.13
8.5.13
ConcreteCMS Concrete Cms<8.5.13
ConcreteCMS Concrete Cms>=9.0<9.2.2
Remediation
Patch Available
Patch Available
Event History
Nov 17, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Advisory Published
06:31 AM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-48649.
2
What is the severity of CVE-2023-48649?
The severity of CVE-2023-48649 is low (3.5).
3
Which versions of Concrete CMS are affected by CVE-2023-48649?
Concrete CMS versions before 8.5.13 and 9.x before 9.2.2 are affected by CVE-2023-48649.
4
How can the stored XSS on the Admin page be exploited?
Stored XSS on the Admin page can be exploited through an uploaded file name.
5
How can CVE-2023-48649 be fixed?
CVE-2023-48649 can be fixed by upgrading to Concrete CMS version 8.5.13 or 9.2.2.