CVE-2022-43695
Summary
| CVE | CVE-2022-43695 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-14 23:15:00 UTC |
| Updated | 2023-08-08 14:22:00 UTC |
| Description | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting (XSS) in dashboard/system/express/entities/associations because Concrete CMS allows association with an entity name that doesn’t exist or, if it does exist, contains XSS since it was not properly sanitized. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Concretecms | Concrete Cms | All | All | All | All |
| Application | Concretecms | Concrete Cms | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release 9.1.3 · concretecms/concretecms · GitHub | MISC | github.com | |
| Release 8.5.10 · concretecms/concretecms · GitHub | MISC | github.com | |
| Concrete CMS Security Advisory 2022-10-31 | MISC | www.concretecms.org | |
| 9.1.3 Release Notes :: Concrete CMS | MISC | documentation.concretecms.org | |
| 8.5.10-12 Release Notes :: Concrete CMS | MISC | documentation.concretecms.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.