CVE-2025-8571 | Concrete CMS up to 8.5.20/9.4.2 on Concrete Conversation Messages Dashboard cross site scripting
A vulnerability was found in Concrete CMS up to 8.5.20/9.4.2 on Concrete and classified as problematic. Affected by this issue is some unknown functionality of the component Conversation Messages Dashboard. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2025-8571. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.