Concrete CMS Cross-Site Request Forgery Vulnerability in Anti-Spam Allowlist Group Configuration

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in Concrete CMS versions prior to 9.4.8. This issue allows a rogue administrator to manipulate the Anti-Spam Allowlist Group Configuration by using the group_id parameter. The vulnerability arises because changes are saved before the CSRF token is validated, leading to a security bypass.

Impact

Exploitation of this vulnerability could result in unauthorized changes to group configurations, bypassing CSRF protections.

Remediation

Users can upgrade to Concrete CMS version 9.4.8 or later to address this vulnerability.

Added: Mar 4, 2026, 3:20 AM
Updated: Mar 4, 2026, 3:20 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.6
exploitability
5.0
remediation
7.7
relevance
3.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.