CVE-2023-49337

Concrete CMS before 9.2.3 allows Stored XSS on the Admin Dashboard via /dashboard/system/basics/name. (8.5 and earlier are unaffected.)
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.4 LOW
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
mitreCNA
2.4 LOW
NETWORK
LOW
HIGH
CVSS:3.1/AC:L/AV:N/A:N/C:N/I:L/PR:H/S:U/UI:R
CVEADP
---
---
CISA-ADPADP
---
---