From 019d19fcc91c161cacd7d8b4a9473b1097fa70f4 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 8 Aug 2024 19:05:50 +0000 Subject: [PATCH] Publish GHSA-9qhc-pg6j-wf23 --- .../2024/04/GHSA-9qhc-pg6j-wf23/GHSA-9qhc-pg6j-wf23.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/advisories/github-reviewed/2024/04/GHSA-9qhc-pg6j-wf23/GHSA-9qhc-pg6j-wf23.json b/advisories/github-reviewed/2024/04/GHSA-9qhc-pg6j-wf23/GHSA-9qhc-pg6j-wf23.json index 45f97b2c010..fa67263eba9 100644 --- a/advisories/github-reviewed/2024/04/GHSA-9qhc-pg6j-wf23/GHSA-9qhc-pg6j-wf23.json +++ b/advisories/github-reviewed/2024/04/GHSA-9qhc-pg6j-wf23/GHSA-9qhc-pg6j-wf23.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-9qhc-pg6j-wf23", - "modified": "2024-04-03T22:06:26Z", + "modified": "2024-08-08T19:04:10Z", "published": "2024-04-03T21:31:41Z", "aliases": [ "CVE-2024-3180" ], "summary": "Concrete CMS Stored XSS in blocks of type file", - "details": "Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type file. Prior to fix, stored XSS could be caused by a rogue administrator adding malicious code to the link-text field when creating a block of type file. The Concrete CMS security team gave this vulnerability a CVSS v3.1 score of 3.1 with a vector of AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator . Thanks Alexey Solovyev for reporting.\n\n", + "details": "Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type file. Stored XSS could be caused by a rogue administrator adding malicious code to the link-text field when creating a block of type file. The Concrete CMS security team gave this vulnerability a CVSS v3.1 score of 3.1 with a vector of AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator . Thanks Alexey Solovyev for reporting.", "severity": [ { "type": "CVSS_V3",