GHSA-9v2g-37mp-qpxfHigh
Concrete CMS has Stored XSS through its height parameter
🔗 CVE IDs covered (1)
📋 Description
Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $height. Any user with editor privileges can inject malicious JavaScript that executes in the context of any visitor's browser, potentially leading to session hijacking, credential theft, or other malicious actions.
🎯 Affected products1
- composer/concrete5/concrete5:< 9.5.1