CVE-2023-28475

Publication date

2023-04-28 00:00:00

Family

mitre

State

PUBLISHED

Description

Concrete CMS (previously concrete5) versions 8.5.12 and below, and versions 9.0 through 9.1.3 is vulnerable to Reflected XSS on the Reply form because msgID was not sanitized.