PT-2026-93112 · Unknown · Concrete Cms
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions 9.0.0 through 9.5.2
Description
An issue exists where block-level edit-permission checks are not enforced on the Express Form block's control-management actions. The system relies exclusively on CSRF (Cross-Site Request Forgery) token validation, but since the token is bound to the user and action rather than a specific block, page, or form, it can be reused. An authenticated user with edit access to one Express Form can use a valid token to add, modify, or delete controls on other Express Forms they are not authorized to edit. This can lead to stored XSS (Cross-Site Scripting), where a malicious script is permanently stored on the server and executed in the browser of other users, by injecting a control whose value is rendered as HTML.
Recommendations
Update Concrete CMS to a version later than 9.5.2.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms