Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-54307
HistoryJun 28, 2022 - 12:00 a.m.

PortlandLabs Concrete CMS Cross-Site Scripting Vulnerability (CNVD-2022-54307)

2022-06-2800:00:00
China National Vulnerability Database
www.cnvd.org.cn
13

0.001 Low

EPSS

Percentile

36.7%

PortlandLabs Concrete CMS is a team-oriented open source content management system from PortlandLabs, Inc. A cross-site scripting vulnerability exists in PortlandLabs Concrete CMS, which originates in /dashboard/system/express/entities/ Forms/save_control lacks a data validation filter for user-supplied data and output, which can be exploited by attackers to execute JavaScript code on the client side.

0.001 Low

EPSS

Percentile

36.7%

Related for CNVD-2022-54307