CVE-2025-2963: ConcreteCMS Legacy Form Block addEditQuestion cross site scripting
Published Mar 30, 2025
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
ConcreteCMS ConcreteCMS<=9.3.9
Event History
Mar 30, 2025
CVE Published
via MITRE·10:00 PM
Rejected
via MITRE·10:00 PM
Data Sourced
via NVD·10:15 PM
Description
Apr 3, 2025
Rejected
via MITRE·10:43 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-2963?
CVE-2025-2963 is classified as a problematic vulnerability affecting certain versions of ConcreteCMS.
2
How does CVE-2025-2963 affect ConcreteCMS?
CVE-2025-2963 affects the addEditQuestion function in the Legacy Form Block Handler, allowing for cross-site scripting attacks.
3
What versions of ConcreteCMS are impacted by CVE-2025-2963?
CVE-2025-2963 impacts ConcreteCMS versions up to and including 9.3.9.
4
How can I mitigate CVE-2025-2963?
To mitigate CVE-2025-2963, ensure that you upgrade to a patched version of ConcreteCMS that addresses this vulnerability.
5
What type of attack does CVE-2025-2963 enable?
CVE-2025-2963 enables cross-site scripting (XSS) attacks if exploited.