CVE-2024-7394: Concrete CMS version 9.0.0 through 9.3.2 and below 8.5.18 - Stored XSS in getAttributeSetName()
Published Aug 8, 2024
·Updated
Concrete CMS versions 9 through 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in getAttributeSetName(). A rogue administrator could inject malicious code.
Affected Software
4 affected componentsFixes available
composer/concrete5/concrete5>=9.0.0<9.3.3
9.3.3
composer/concrete5/concrete5<8.5.18
8.5.18
ConcreteCMS Concrete CMS<8.5.18
ConcreteCMS Concrete CMS>=9.0.0<9.3.3
Remediation
Patch Available
Event History
Aug 8, 2024
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-7394?
CVE-2024-7394 has a severity rating that indicates it poses a risk of Stored XSS vulnerabilities, allowing malicious code injection.
2
How do I fix CVE-2024-7394?
To fix CVE-2024-7394, upgrade to Concrete CMS versions 9.3.3 or 8.5.18 or later.
3
Who is affected by CVE-2024-7394?
CVE-2024-7394 affects Concrete CMS versions 9 through 9.3.2 and below 8.5.18.
4
What kind of attacks can be executed through CVE-2024-7394?
CVE-2024-7394 allows a rogue administrator to execute Stored XSS attacks, injecting malicious scripts into the application.
5
What components are involved in CVE-2024-7394?
CVE-2024-7394 involves the getAttributeSetName() function within specified versions of Concrete CMS.