CVE-2014-5108: CONCRETE5
Medium severity, CVSS 4.3. EPSS: 2.3% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in single_pages\download_file.php in concrete5 before 5.6.3 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to index.php/download_file.
Affected products
- CONCRETE5 CONCRETE5: version 5.5.0 only; version 5.5.1 only; version 5.5.2 only; version 5.5.2.1 only; version 5.6.0 only; version 5.6.0.1 only; …
- Concretecms Concrete CMS: version 5.4.2 only; version 5.4.2.1 only; version 5.4.2.2 only; version 5.6.1 only; version 5.6.1.1 only; version 5.6.1.2 only; …
Published 2014-07-28. Last modified 2026-06-17.