A vulnerability, which was classified as problematic, was found in Concrete CMS up to 9.2.4. This affects an unknown part. The manipulation of the argument Role Name leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2024-1247. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.