Security Advisory

CVE-2022-43968

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-11-14 00:00:00
Last updated 2025-05-13 19:25:59
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the dashboard icons due to un-sanitized output. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.