CVE-2025-2964: ConcreteCMS FAQ Block save cross site scripting
Published Mar 30, 2025
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
ConcreteCMS ConcreteCMS<=9.3.9
Event History
Mar 30, 2025
CVE Published
via MITRE·10:31 PM
Rejected
via MITRE·10:31 PM
Data Sourced
via NVD·11:15 PM
Description
Apr 4, 2025
Rejected
via MITRE·12:02 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-2964?
CVE-2025-2964 is classified as problematic due to its potential for cross site scripting.
2
How do I fix CVE-2025-2964?
To mitigate CVE-2025-2964, update ConcreteCMS to a version higher than 9.3.9.
3
What component is affected by CVE-2025-2964?
CVE-2025-2964 affects the FAQ Block Handler component in ConcreteCMS.
4
What type of vulnerability is CVE-2025-2964?
CVE-2025-2964 is a cross site scripting vulnerability.
5
What argument manipulation leads to CVE-2025-2964?
The manipulation of the Navigation/Title Text/Description Source argument leads to CVE-2025-2964.