PT-2026-92121 · Concrete Cms+1 · Concrete Cms
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions 9.0.0 through 9.5.2
Description
An authorization check is missing on the user selector autocomplete endpoint '/ccm/system/user/autocomplete', which supports the Preview as User panel and other user-selector components. The endpoint only validates a CSRF-style access token bound to display options rather than the caller's identity or permissions. Since this token is issued to anonymous visitors, an unauthenticated attacker can submit an empty search query to trigger a match-all filter. By paginating the results, the attacker can enumerate all backend accounts, disclosing the internal user ID, username, and email address of administrative users, including the super-administrator.
Recommendations
Update Concrete CMS versions 9.0.0 through 9.5.2 to a version where this issue is resolved.
Restrict access to the '/ccm/system/user/autocomplete' endpoint to minimize the risk of account enumeration.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms