PT-2026-93870 · Concrete Cms+1 · Concrete Cms
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions prior to 9.5.3
Description
A legacy Express entry search endpoint returns entry result JSON without invoking the
canViewExpressEntries() permission check. This allows an unauthenticated visitor who possesses an Express entity identifier to enumerate search results and disclose attribute values intended for privileged users. For Express entities where supportsEntrySpecificPermissions() returns false, per-entry permission filtering is further disabled through the EntryList::ignorePermissions() function.Recommendations
Update to version 9.5.3 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms