Concrete CMS
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*
- <= 9.5.0
A stored cross-site scripting vulnerability has been identified in Concrete CMS versions through 9.5.0, specifically within the OAuth integration name. The issue arises because the OAuth authorize template displays the integration name, which is controlled by the admin, using Concrete's translation helper in a way that allows for raw HTML to be injected. This flaw could enable a malicious admin to intercept login submissions.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the affected page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.