CVE-2023-44764

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
06/10/2023
Last modified:
02/02/2024

Description

A Cross Site Scripting (XSS) vulnerability in Concrete CMS before 9.2.3 exists via the Name parameter during installation (aka Site of Installation or Settings).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:concretecms:concrete_cms:9.2.1:*:*:*:*:*:*:*