CVE-2024-8291: Concrete CMS Stored XSS in Image Editor Background Color
Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color. A rogue admin could add malicious code to the Thumbnails/Add-Type.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8291?
CVE-2024-8291 is classified as a Stored XSS vulnerability, which can allow an attacker to execute malicious scripts in the context of another user.
How do I fix CVE-2024-8291?
To mitigate CVE-2024-8291, upgrade to Concrete CMS version 9.3.4 or later, or version 8.5.20 or later.
Which versions of Concrete CMS are affected by CVE-2024-8291?
Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to CVE-2024-8291.
What are the potential impacts of CVE-2024-8291?
The potential impacts of CVE-2024-8291 include unauthorized access to sensitive user data and potential account takeovers.
Who can exploit the vulnerability in CVE-2024-8291?
A rogue admin with access to the Image Editor in the affected versions can exploit the vulnerability by adding malicious code.