CVE-2025-2965: ConcreteCMS Accordion Block save cross site scripting
Published Mar 30, 2025
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
ConcreteCMS ConcreteCMS<=9.3.9
Event History
Mar 30, 2025
CVE Published
via MITRE·11:00 PM
Rejected
via MITRE·11:00 PM
Data Sourced
via NVD·11:15 PM
Description
Apr 4, 2025
Rejected
via MITRE·12:04 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-2965?
CVE-2025-2965 is classified as problematic due to exposure to cross-site scripting vulnerabilities.
2
What versions of ConcreteCMS are affected by CVE-2025-2965?
CVE-2025-2965 affects ConcreteCMS versions up to and including 9.3.9.
3
How do I fix CVE-2025-2965?
To fix CVE-2025-2965, update ConcreteCMS to a version beyond 9.3.9 that addresses the vulnerability.
4
What type of attack does CVE-2025-2965 enable?
CVE-2025-2965 enables cross-site scripting (XSS) attacks through improper handling of user input in the Accordion Block Handler.
5
Where is the CVE-2025-2965 vulnerability located in ConcreteCMS?
CVE-2025-2965 is located in the Save function of the Accordion Block Handler component.