OSV 1.4.0 · github-reviewed · 修改于 2026-06-25 04:58
发布时间
2026-05-22 05:30
GitHub 审查时间
2026-06-25 02:10
NVD 发布时间
2026-05-22 05:16
源文件
advisories/github-reviewed/2026/05/GHSA-9v2g-37mp-qpxf/GHSA-9v2g-37mp-qpxf.json
Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $height. Any user with editor privileges can inject malicious JavaScript that executes in the context of any visitor's browser, potentially leading to session hijacking, credential theft, or other malicious actions.