CVE-2023-44763
MEDIUMConcretecms Concrete Cms - Unrestricted File Upload
Title source: ruleDescription
Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE: the vendor's position is that a customer is supposed to know that "pdf" should be excluded from the allowed file types, even though pdf is one of the allowed file types in the default configuration.
Exploits (1)
nomisec
WRITEUP
by sromanhu · poc
https://github.com/sromanhu/CVE-2023-44763_ConcreteCMS-Arbitrary-file-upload-Thumbnail
References (3)
Scores
CVSS v3
5.4
EPSS
0.0027
EPSS Percentile
50.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-434
Status
published
Products (2)
concrete5/concrete5
0Packagist
concretecms/concrete_cms
9.2.1
Published
Oct 10, 2023
Tracked Since
Feb 18, 2026