Concrete CMS
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*
- <= 9.5.0
A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in Concrete CMS versions through 9.5.0. This vulnerability exists in the Express Entry Detail block, specifically through the exEntryID parameter, and leads to unauthorized access to all submissions of Express forms.
Exploitation of this vulnerability allows unauthorized users to access all submissions of Express forms, potentially leading to data exposure or misuse.
Users can upgrade to Concrete CMS version 9.5.1 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.