CVE-2024-4353
Last modified
CVE-2024-4353 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in the generate dashboard board instance functionality. The Name input field does not check the input sufficiently letting a rogue administrator have the capability to inject malicious JavaScript code. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in the generate dashboard board instance functionality. The Name input field does not check the input sufficiently letting a rogue administrator have the capability to inject malicious JavaScript code. The Concrete CMS security team gave this vulnerability a CVSS v4 score of 4.6 with a vector of CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Concrete versions below 9 are not affected by this vulnerability.Thanks fhAnso for reporting. (CNA updated this risk rank on 17 Jan 2025 by lowering the AC based on CVSS 4.0 documentation that access privileges should not be considered for AC).
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Concretecms | Concrete Cms | >= 9.0.0, < 9.3.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-4353?
How severe is CVE-2024-4353?
How do I fix CVE-2024-4353?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-43524Windows Mobile Broadband Driver Remote Code Execution Vulner…6.8
- CVE-2024-43525Windows Mobile Broadband Driver Remote Code Execution Vulner…6.8
- CVE-2024-43526Windows Mobile Broadband Driver Remote Code Execution Vulner…6.8
- CVE-2024-43527Windows Kernel Elevation of Privilege Vulnerability7.8
- CVE-2024-43528Windows Secure Kernel Mode Elevation of Privilege Vulnerabil…7.8
- CVE-2024-43529Windows Print Spooler Elevation of Privilege Vulnerability7.3
- CVE-2024-43530Windows Update Stack Elevation of Privilege Vulnerability7.8
- CVE-2024-43532Remote Registry Service Elevation of Privilege Vulnerability8.8
- CVE-2024-43533Remote Desktop Client Remote Code Execution Vulnerability8.8
- CVE-2024-43534Windows Graphics Component Information Disclosure Vulnerabil…6.5
- CVE-2024-43535Windows Kernel-Mode Driver Elevation of Privilege Vulnerabil…7
- CVE-2024-43536Windows Mobile Broadband Driver Remote Code Execution Vulner…6.8
Are you affected by CVE-2024-4353?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
