Description
The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/view/ URI.
Remediation
References
Related Vulnerabilities
WordPress Plugin Add Product Tabs for WooCommerce Security Bypass (1.4.2)
WordPress Plugin ProfileGrid-User Profiles, Groups and Communities Privilege Escalation (5.8.9)
Grafana Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2022-21673)
WordPress Plugin Country State City Dropdown CF7 SQL Injection (2.7.2)