CVE-2025-8573: Concrete CMS 9 through 9.4.2 is vulnerable to Stored XSS from Home Folder on Members Dashboard page
Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS from Home Folder on Members Dashboard page. Version 8 was not affected. A rogue admin could set up a malicious folder containing XSS to which users could be directed upon login.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/concrete5/concrete5to a version that resolves this vulnerability.Fixed in 9.4.3
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8573?
CVE-2025-8573 is classified as a high severity vulnerability due to its potential to exploit stored XSS in Concrete CMS.
How do I fix CVE-2025-8573?
To fix CVE-2025-8573, upgrade your Concrete CMS to version 9.4.3 or later, which addresses the vulnerability.
Who is affected by CVE-2025-8573?
CVE-2025-8573 affects all versions of Concrete CMS from 9.0.0 to 9.4.2 but does not impact version 8.
What type of attack is possible with CVE-2025-8573?
CVE-2025-8573 allows for stored XSS attacks, where malicious scripts can be stored and executed on the Members Dashboard page.
Can administrators exploit CVE-2025-8573?
Yes, a rogue administrator could exploit CVE-2025-8573 by creating a malicious folder that redirects users to an XSS payload.