PT-2026-93854 · Concrete Cms+1 · Concrete Cms
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions 9.2.0 through 9.5.3
Description
The REST API user creation endpoint 'POST /ccm/api/1.0/users', specifically the
add() function in concrete/src/Api/Controller/Users.php, fails to perform a permission check before creating an account. This allows any valid OAuth token with the users:add scope, including client credentials tokens without an associated user context, to create active and validated user accounts. This process bypasses email verification and administrator approval. With default registration settings, these accounts can edit page content, which may lead to stored cross-site scripting (XSS)—a technique where malicious scripts are permanently stored on a target server—and further system compromise.Recommendations
Update Concrete CMS versions 9.2.0 through 9.5.3 to a version where this issue is resolved.
As a temporary workaround, restrict access to the 'POST /ccm/api/1.0/users' endpoint or limit the distribution of OAuth tokens with the
users:add scope.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms