CVE-2025-8573

Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS from Home Folder on Members Dashboard page.  Version 8 was not affected. A rogue admin could set up a malicious folder containing XSS to which users could be directed upon login. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.0 with vector CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks sealldev  (Noah Cooper) for reporting via HackerOne.
CVSS

No CVSS.

Configurations

No configuration.

History

11 Aug 2025, 18:15

Type Values Removed Values Added
Summary (en) Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS from Home Folder on Members Dashboard page.  Version 8 was not affected. A rogue admin could set up a malicious folder containing XSS to which users could be directed upon login. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.0 with vector CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks sealldev for reporting via HackerOne. (en) Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS from Home Folder on Members Dashboard page.  Version 8 was not affected. A rogue admin could set up a malicious folder containing XSS to which users could be directed upon login. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.0 with vector CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks sealldev  (Noah Cooper) for reporting via HackerOne.

06 Aug 2025, 20:23

Type Values Removed Values Added
Summary
  • (es) Las versiones 9 a 9.4.2 de Concrete CMS son vulnerables a XSS almacenado desde la carpeta de inicio en la página del Panel de Miembros. La versión 8 no se vio afectada. Un administrador malicioso podría crear una carpeta maliciosa con XSS a la que se redirigiría a los usuarios al iniciar sesión. El equipo de seguridad de Concrete CMS otorgó a esta vulnerabilidad una puntuación de 2.0 en CVSS v.4.0 con el vector CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Gracias a sealldev por informar a través de HackerOne.

05 Aug 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-05 23:15

Updated : 2025-08-11 18:15


NVD link : CVE-2025-8573

Mitre link : CVE-2025-8573

CVE.ORG link : CVE-2025-8573


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation