CVE-2025-2969: ConcreteCMS Feature Link Block save cross site scripting
Published Mar 31, 2025
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
ConcreteCMS ConcreteCMS<=9.3.9
Event History
Mar 31, 2025
CVE Published
via MITRE·01:00 AM
Rejected
via MITRE·01:00 AM
Data Sourced
via NVD·02:15 AM
Description
Apr 4, 2025
Rejected
via MITRE·12:12 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-2969?
CVE-2025-2969 has been rated as problematic.
2
How does CVE-2025-2969 affect ConcreteCMS?
CVE-2025-2969 affects the Save function of the Feature Link Block Handler in ConcreteCMS versions up to 9.3.9.
3
What type of attack is associated with CVE-2025-2969?
CVE-2025-2969 may lead to cross-site scripting attacks due to manipulations of specific arguments.
4
How can I mitigate CVE-2025-2969?
To mitigate CVE-2025-2969, update ConcreteCMS to version 9.4.0 or later.
5
What should I do if I am using an affected version of ConcreteCMS and cannot update immediately due to CVE-2025-2969?
If immediate updating is not feasible, consider implementing input validation and sanitization to prevent cross-site scripting.