CVE-2023-49337

LOW2.4EPSS 0.46%

Concrete CMS Stored XSS

發布日:2024/2/29修改日:2024/12/16

描述

Concrete CMS before 9.2.3 allows Stored XSS on the Admin Dashboard via /dashboard/system/basics/name. (8.5 and earlier are unaffected.)

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1LOW2.4CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

參考連結(6)