CVE-2025-3153

MEDIUM EPSS 5.0%
Published Apr 3, 20251y ago · Modified Jun 17, 20261w ago
5.1 CVSS 4.0
Medium
Find Similar
Published Apr 3, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 are vulnerable to CSRF and XSS in the Concrete CMS Address attribute because addresses are not properly sanitized in the output when a country is not specified.  Attackers are limited to individuals whom a site administrator has granted the ability to fill in an address attribute. It is possible for the attacker to glean limited information from the site but amount and type is restricted by mitigating controls and the level of access of the attacker. Limited data modification is possible. The dashboard page itself could be rendered unavailable. The fix only sanitizes new data uploaded post update to Concrete CMS 9.4.0RC2. Existing database entries added before the update will still be “live” if there were successful exploits added under previous versions; a database search is recommended. The Concrete CMS security team gave this vulnerability CVSS v.4.0 score of 5.1 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L Thanks Myq Larson for reporting.

CVSS Details

Base Score
5.1
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction P
Scope X

Threat Intelligence

EPSS Exploit Probability
5.0% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 2

CWE-352 Cross-Site Request Forgery (CSRF) Authentication
CWE-79 Cross-site Scripting Injection

Affected Products 3

VendorProductVersionRange
concretecmsconcrete_cms* <8.5.20
concretecmsconcrete_cms*≥9.0  –  <9.4.0
concretecmsconcrete_cms9.4.0any

References 4

  • documentation.concretecms.org https://documentation.concretecms.org/9-x/developers/introduction/version-history/940-release-notes
    Release Notes
  • github.com https://github.com/concretecms/concretecms/pull/12511
    Issue TrackingPatch
  • github.com https://github.com/concretecms/concretecms/pull/12512
    Issue TrackingPatch
  • github.com https://github.com/concretecms/concretecms/releases/tag/8.5.20
    Release Notes

Remediation

  • github.com https://github.com/concretecms/concretecms/pull/12511
    Issue TrackingPatch
  • github.com https://github.com/concretecms/concretecms/pull/12512
    Issue TrackingPatch