First published: Mon Mar 31 2025(Updated: )
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Credit: ff5b8ace-8b95-4078-9743-eac1ca5451de
Affected Software | Affected Version | How to fix |
---|---|---|
ConcreteCMS | <=9.3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2971 is classified as problematic, indicating a significant security risk.
To fix CVE-2025-2971, upgrade ConcreteCMS to version 9.4.0 or later.
CVE-2025-2971 is a cross-site scripting (XSS) vulnerability affecting the List Block Handler component.
CVE-2025-2971 affects all versions of ConcreteCMS up to and including 9.3.9.
Yes, CVE-2025-2971 can be exploited remotely, allowing attackers to manipulate user input in the affected component.