2024-02-29 03:01:19 +00:00
{
"id" : "CVE-2023-48650" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2024-02-29T01:41:34.060" ,
2024-02-29 15:04:26 +00:00
"lastModified" : "2024-02-29T13:49:47.277" ,
"vulnStatus" : "Awaiting Analysis" ,
2024-02-29 03:01:19 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Concrete CMS before 8.5.14 and 9 before 9.2.3 is vulnerable to an admin adding a stored XSS payload via the Layout Preset name."
2024-04-04 08:46:00 +00:00
} ,
{
"lang" : "es" ,
"value" : "Concrete CMS anterior a 8.5.14 y 9 anterior a 9.2.3 es vulnerable a que un administrador agregue un payload XSS almacenado a trav\u00e9s del nombre del dise\u00f1o preestablecido."
2024-02-29 03:01:19 +00:00
}
] ,
"metrics" : { } ,
"references" : [
{
"url" : "https://documentation.concretecms.org/developers/introduction/version-history/923-release-notes" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://www.concretecms.org/about/project-news/security/2023-12-05-concrete-cms-new-cves-and-cve-updates" ,
"source" : "cve@mitre.org"
}
]
}