CyberRota Analysis
AI analysis pending.
CVE
CVE-2023-28475
Severity
MEDIUM
CVSS
6.1
EPSS
0.64%
Original NVD Description
Concrete CMS (previously concrete5) versions 8.5.12 and below, and versions 9.0 through 9.1.3 is vulnerable to Reflected XSS on the Reply form because msgID was not sanitized.