Description
Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTML data with a SCRIPT element.
Remediation
References
Related Vulnerabilities
WordPress Plugin YITH WooCommerce Subscription Security Bypass (1.3.4)
WordPress Plugin RSS Includes Pages Cross-Site Scripting (3.6)
WordPress Plugin Related Posts Unspecified Vulnerability (5.12.69)
WordPress Plugin WooCommerce Admin Security Bypass (2.6.3)
WordPress Plugin Appointment Booking Calendar SQL Injection (1.1.23)