packetstormsecurity.com
http://packetstormsecurity.com/files/161600/Concrete5-8.5.4-Cross-Site-Scripting.html CVE-2021-3111
MEDIUM
Concrete5 8.5.4 - 'name' Stored XSS
Record summary
CVE-2021-3111 has a selected CVSS score of 4.8 (medium); EIP currently links 1 catalogued exploit.
Description
The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/view/ URI.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBConcrete5 8.5.4 - 'name' Stored XSSExploitDB exploitby Quadron Research LabNot analyzed1 file
References
6packetstormsecurity.com
http://packetstormsecurity.com/files/161997/Concrete5-8.5.4-Cross-Site-Scripting.html documentation.concrete5.org
https://documentation.concrete5.org/developers/introduction/version-history documentation.concrete5.org
https://documentation.concrete5.org/developers/introduction/version-history/855-release-notes github.com
https://github.com/Quadron-Research-Lab/CVE/blob/main/CVE-2021-3111.pdf nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-3111