CVE-2025-3153 is a Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) vulnerability affecting Concrete CMS versions below 9.4.0RC2 and 8.5.20, stemming from improper sanitization of address attributes when a country is not specified. This medium-severity vulnerability (CVSS 6.5) requires attacker interaction and limited privileges, potentially leading to limited information disclosure, data modification, and denial of service on the dashboard page. While a fix is available, it only applies to new data, necessitating a database search for pre-existing exploits. There is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5, < 8.5.20CPE match | cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:* | ||
< 8.5.20CPE matchmatch criteria | cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:* | ||
>= 9.0, < 9.4.0CPE matchmatch criteria | cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:* | ||
9.4.0CPE matchmatch criteria | cpe:2.3:a:concretecms:concrete_cms:9.4.0:rc1:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.