Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Tags on uploaded files.
2023-04-28T14:15:10.557
2024-11-21T07:55:10.610
Modified
CVSSv3.1: 5.4 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | concretecms | concrete_cms | < 9.2.0 | Yes |