First published: Fri Aug 09 2024(Updated: )
Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in Board instances. A rogue administrator could inject malicious code.
Credit: ff5b8ace-8b95-4078-9743-eac1ca5451de ff5b8ace-8b95-4078-9743-eac1ca5451de
Affected Software | Affected Version | How to fix |
---|---|---|
composer/concrete5/concrete5 | >=9.0.0RC1<9.3.3 | 9.3.3 |
Concrete5 | >=9.0.0<9.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7512 has been classified as a high severity vulnerability due to its potential for stored XSS attacks.
To fix CVE-2024-7512, upgrade to Concrete CMS version 9.3.3 or later.
Concrete CMS versions 9.0.0 through 9.3.2 are affected by CVE-2024-7512.
CVE-2024-7512 is a stored cross-site scripting (XSS) vulnerability.
CVE-2024-7512 can be exploited by a rogue administrator with access to Board instances.