CVE-2023-28475 Information

Description

Concrete CMS (previously concrete5) before 9.2 is vulnerable to Reflected XSS on the Reply form because msgID was not sanitized.

Reference

https://concretecms.com https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2023-04-20

Share on: