CVE-2025-2972: ConcreteCMS Page Attribute Display Block cross site scripting
Published Mar 31, 2025
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
ConcreteCMS ConcreteCMS<=9.3.9
Event History
Mar 31, 2025
CVE Published
via MITRE·02:31 AM
Rejected
via MITRE·02:31 AM
Data Sourced
via NVD·03:15 AM
Description
Apr 4, 2025
Rejected
via MITRE·12:29 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-2972?
CVE-2025-2972 is classified as a problematic vulnerability.
2
What component is affected by CVE-2025-2972?
CVE-2025-2972 affects the Page Attribute Display Block Handler component in ConcreteCMS.
3
What type of vulnerability is CVE-2025-2972?
CVE-2025-2972 is a cross-site scripting (XSS) vulnerability.
4
How do I fix CVE-2025-2972?
To fix CVE-2025-2972, update ConcreteCMS to a version later than 9.3.9.
5
What versions of ConcreteCMS are affected by CVE-2025-2972?
ConcreteCMS versions up to and including 9.3.9 are affected by CVE-2025-2972.