logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-44766

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-44766

Description:
A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a crafted script to the SEO - Extra from Page Settings. NOTE: the vendor disputes this because this SEO-related header change can only be made by an admin, and allowing an admin to place JavaScript there is an intentional customization feature.
Last updated date:
08/02/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
10/06/2023
Reference url to background

https://github.com/sromanhu/ConcreteCMS-Stored-XSS---SEO

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy