Andrew Embler
6 exploits
Active since Feb 2024
Concrete CMS 9.0.0-9.2.2 - Stored Cross-Site Scripting via Admin Dashboard Name Field
CVSS 2.4
Concrete CMS < 8.5.18 and 9.0.0-9.3.2 - Authenticated Stored Cross-Site Scripting in RSS Displayer
CVSS 4.8
Concrete CMS < 8.5.18 and 9.0.0-9.3.2 - Authenticated Stored Cross-Site Scripting in getAttributeSetName()
CVSS 4.8
Concrete CMS < 8.5.19 and 9.0.0-9.3.3 - Stored Cross-Site Scripting in Calendar Event Name
CVSS 5.4
Concrete CMS <9.3.3 & <8.5.19 - Stored XSS
CVSS 4.8
Concrete CMS <9.3.3, <8.5.19 - Stored XSS
CVSS 4.8