Cross-Site Scripting Vulnerability in Concrete5 Legacy by Concrete CMS
CVE-2021-41465

6.1MEDIUM

Key Information:

Vendor
CVE Published:
1 October 2021

What is CVE-2021-41465?

The vulnerability allows remote attackers to exploit a cross-site scripting (XSS) flaw in Concrete5 Legacy versions 5.6.4.0 and earlier. This is achieved through the 'rel' parameter, where arbitrary web scripts or HTML can be injected. These malicious scripts can compromise user sessions, redirect victims, or perform unwanted actions by executing in the context of the affected user's browser. Developers and website administrators are urged to apply available patches and adopt best security practices to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.