CVE-2023-28820 | Concrete CMS up to 9.0 RSS Displayer href cross site scripting (EUVD-2023-1289)
A vulnerability has been found in Concrete CMS up to 9.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component RSS Displayer. The manipulation of the argument href leads to cross site scripting.
This vulnerability is known as CVE-2023-28820. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.