CVE-2025-2970: ConcreteCMS Switch Language Block cross site scripting
Published Mar 31, 2025
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
ConcreteCMS ConcreteCMS<=9.3.9
Event History
Mar 31, 2025
CVE Published
via MITRE·01:31 AM
Rejected
via MITRE·01:31 AM
Data Sourced
via NVD·02:15 AM
Description
Apr 4, 2025
Rejected
via MITRE·12:31 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-2970?
CVE-2025-2970 is classified as a problematic vulnerability.
2
How do I fix CVE-2025-2970?
Fixing CVE-2025-2970 involves upgrading ConcreteCMS to a version higher than 9.3.9.
3
What components are affected by CVE-2025-2970?
CVE-2025-2970 affects the Switch Language Block Handler component of ConcreteCMS.
4
What type of attack is possible due to CVE-2025-2970?
CVE-2025-2970 allows for remote cross site scripting attacks.
5
Which versions of ConcreteCMS are vulnerable according to CVE-2025-2970?
ConcreteCMS versions up to and including 9.3.9 are vulnerable according to CVE-2025-2970.