{ "id": "CVE-2023-28475", "sourceIdentifier": "cve@mitre.org", "published": "2023-04-28T14:15:10.523", "lastModified": "2023-04-28T17:06:28.060", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "Concrete CMS (previously concrete5) before 9.2 is vulnerable to Reflected XSS on the Reply form because msgID was not sanitized." } ], "metrics": {}, "references": [ { "url": "https://concretecms.com", "source": "cve@mitre.org" }, { "url": "https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2023-04-20", "source": "cve@mitre.org" } ] }