Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-99285
HistorySep 26, 2021 - 12:00 a.m.

Concrete CMS Cross-Site Scripting Vulnerability

2021-09-2600:00:00
China National Vulnerability Database
www.cnvd.org.cn
3

0.001 Low

EPSS

Percentile

22.7%

Concrete CMS is an open source content management system for teams.A stored cross-site scripting vulnerability exists in Conversations in Concrete CMS 8.5.5 and earlier versions when the “Active Conversation Editor” is set to rich text. An attacker could exploit this vulnerability to insert malicious code.

CPENameOperatorVersion
portland labs concrete cmsle8.5.5

0.001 Low

EPSS

Percentile

22.7%

Related for CNVD-2021-99285