5.4
CVSSv3

CVE-2023-48649

Published: 17/11/2023 Updated: 22/11/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Concrete CMS prior to 8.5.13 and 9.x prior to 9.2.2 allows stored XSS on the Admin page via an uploaded file name.

Vulnerable Product Search on Vulmon Subscribe to Product

concretecms concrete cms