PT-2026-91564 · Unknown · Concrete Cms
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions 9 through 9.5.2
Description
Concrete CMS fails to validate a Cross-Site Request Forgery (CSRF) token—a unique value used to verify that a request was intentionally sent by the user—in the
removeOrphanedBlocks action within the orphaned block removal panel. A remote attacker can craft a request that, if loaded by an authenticated user with edit permissions on a target page, deletes all blocks on the current version of that page. Blocks not aliased to another page or scrapbook entry are permanently removed from the global Blocks table and their block-type data table, resulting in permanent content destruction.Recommendations
Update Concrete CMS to version 9.5.3 or later.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms