sromanhu / CVE-2023-44760_ConcreteCMS-Stored-XSS---TrackingCodes

Multiple Cross Site Scripting vulnerability in ConcreteCMS v.9.2.1 allows a local attacker to execute arbitrary code via a crafted script to the Header and Footer Tracking Codes of the SEO & Statistics
0 stars 0 forks source link

Responsible disclosure #1

Open KorvinSzanto opened 1 year ago

KorvinSzanto commented 1 year ago

ConcreteCMS has a security program over at https://hackerone.com/concretecms, please use that to report suspected security issues.

This specific CVE is not a vulnerability, the header tracking code's sole functionality is to allow an admin to add javascript to all pages.

KorvinSzanto commented 1 year ago

It's also worth noting that the session cookie Concrete uses is marked as HttpOnly and not accessible via javascript. The cookie you show is unrelated to Concrete CMS.