← Back

CVE-2023-28475

nvd nist
Published: Apr 28, 2023Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Concrete CMS (previously concrete5) versions 8.5.12 and below, and versions 9.0 through 9.1.3 is vulnerable to Reflected XSS on the Reply form because msgID was not sanitized.

Affected (1)

1 product
Concrete Cms
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 9.2.0

Timeline

No history available yet.