First published: Mon Mar 31 2025(Updated: )
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Credit: ff5b8ace-8b95-4078-9743-eac1ca5451de
Affected Software | Affected Version | How to fix |
---|---|---|
ConcreteCMS | <=9.3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2968 is classified as a problematic vulnerability that enables cross-site scripting in ConcreteCMS.
To mitigate CVE-2025-2968, upgrade ConcreteCMS to version 9.4.0 or later, where the vulnerability is addressed.
CVE-2025-2968 affects the Feature Block Handler component in ConcreteCMS.
CVE-2025-2968 allows attackers to perform cross-site scripting (XSS) attacks due to improper handling of user input.
ConcreteCMS versions up to and including 9.3.9 are vulnerable to CVE-2025-2968.