Description
The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/view/ URI.
Remediation
References
Related Vulnerabilities
WordPress Plugin Zero BS WordPress CRM Cross-Site Request Forgery (2.99.9)
Oracle JRE CVE-2013-1569 Vulnerability (CVE-2013-1569)
WebLogic CVE-2024-21260 Vulnerability (CVE-2024-21260)
OpenSSL Numeric Errors Vulnerability (CVE-2009-0789)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-3829)