{ "id": "CVE-2023-44764", "sourceIdentifier": "cve@mitre.org", "published": "2023-10-06T13:15:12.863", "lastModified": "2023-10-06T13:17:35.473", "vulnStatus": "Undergoing Analysis", "descriptions": [ { "lang": "en", "value": "A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a crafted script to the SITE parameter from installation or in the Settings." } ], "metrics": {}, "references": [ { "url": "https://github.com/sromanhu/ConcreteCMS-Stored-XSS---Site_Installation", "source": "cve@mitre.org" } ] }