CVE-2024-3179: Concrete CMS version 9 before 9.2.8 and previous versions before 8.5.16 are vulnerable to Stored XSS in the Custom Class page
Concrete CMS version 9 before 9.2.8 and previous versions before 8.5.16 are vulnerable to Stored XSS in the Custom Class page editing. Prior to the fix, a rogue administrator could insert malicious code in the custom class field due to insufficient validation of administrator provided data. The Concrete CMS security team gave this vulnerability a CVSS v3.1 score of 3.1 with a vector of AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator . Thanks Alexey Solovyev for reporting.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability severity of CVE-2024-3179?
CVE-2024-3179 has a severity rating that identifies it as a significant risk due to the potential for Stored XSS attacks.
How can I mitigate CVE-2024-3179?
To mitigate CVE-2024-3179, upgrade to Concrete CMS version 9.2.8 or 8.5.16 or later.
What types of systems are affected by CVE-2024-3179?
CVE-2024-3179 affects Concrete CMS versions prior to 9.2.8 and 8.5.16.
What kind of attack does CVE-2024-3179 enable?
CVE-2024-3179 enables attackers to execute Stored XSS attacks through the Custom Class page editing feature.
Is there any specific validation issue noted in CVE-2024-3179?
Yes, CVE-2024-3179 arises from insufficient validation of input provided by administrators in the custom class field.