First published: Tue Sep 24 2024(Updated: )
Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color. A rogue admin could add malicious code to the Thumbnails/Add-Type.
Credit: ff5b8ace-8b95-4078-9743-eac1ca5451de ff5b8ace-8b95-4078-9743-eac1ca5451de
Affected Software | Affected Version | How to fix |
---|---|---|
composer/concrete5/concrete5 | <8.5.19 | 8.5.19 |
composer/concrete5/concrete5 | >=9.0.0<9.3.4 | 9.3.4 |
Concrete5 | >=9.0.0<9.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8291 is classified as a Stored XSS vulnerability, which can allow an attacker to execute malicious scripts in the context of another user.
To mitigate CVE-2024-8291, upgrade to Concrete CMS version 9.3.4 or later, or version 8.5.20 or later.
Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to CVE-2024-8291.
The potential impacts of CVE-2024-8291 include unauthorized access to sensitive user data and potential account takeovers.
A rogue admin with access to the Image Editor in the affected versions can exploit the vulnerability by adding malicious code.