CVE-2023-49337
29.02.2024, 01:41
Concrete CMS before 9.2.3 allows Stored XSS on the Admin Dashboard via /dashboard/system/basics/name. (8.5 and earlier are unaffected.)
Vendor | Product | Version |
---|---|---|
concretecms | concrete_cms | 9.0.0 ≤ 𝑥 < 9.2.3 |
𝑥
= Vulnerable software versions
References