CVE-2026-85385 | Concrete CMS up to 9.5.3 Dashboard getTimezoneDisplayName uTimezone cross site scripting

SecurityVulns

A vulnerability labeled as problematic has been found in Concrete CMS up to 9.5.3. The affected element is the function Date::getTimezoneDisplayName of the component Dashboard. The manipulation of the argument uTimezone results in cross site scripting.

This vulnerability was named CVE-2026-85385. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More