CVE-2025-8571: Concrete CMS 9 through 9.4.2 and below 8.5.21 is vulnerable to Reflected Cross-Site Scripting (XSS) in Conversation Messages Dashboard Page
Concrete CMS 9 to 9.4.2 and versions below 8.5.21 are vulnerable to Reflected Cross-Site Scripting (XSS) in the Conversation Messages Dashboard Page. Unsanitized input could cause theft of session cookies or tokens, defacement of web content, redirection to malicious sites, and (if victim is an admin), the execution of unauthorized actions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/concrete5/concrete5to a version that resolves this vulnerability.Fixed in 9.4.3 - Upgrade
Upgrade
composer/concrete5/concrete5to a version that resolves this vulnerability.Fixed in 8.5.21
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8571?
CVE-2025-8571 is classified as a high severity vulnerability due to its potential for exploiting reflected cross-site scripting (XSS).
How do I fix CVE-2025-8571?
To fix CVE-2025-8571, update Concrete CMS to version 9.4.3 or later, or 8.5.21 or later for the affected versions below.
What types of attacks are possible with CVE-2025-8571?
CVE-2025-8571 allows for attacks such as session cookie theft, content defacement, and redirection to malicious sites.
Which versions of Concrete CMS are affected by CVE-2025-8571?
CVE-2025-8571 affects Concrete CMS versions from 9.0 to 9.4.2 and versions below 8.5.21.
Can CVE-2025-8571 lead to data loss?
Yes, CVE-2025-8571 can lead to data loss through session hijacking and potential unauthorized access to user accounts.