Concrete CMS Cross-Site Request Forgery Vulnerability in File Deletion Controller

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Concrete CMS versions through 9.5.0. The issue arises from an inverted CSRF token validation in the DeleteFile controller, where the system erroneously processes file deletions when the token is invalid or absent. This flaw effectively nullifies CSRF protection for the file deletion endpoint, enabling unauthorized file deletions by exploiting users' permissions to edit conversation messages.

Impact

Exploitation of this vulnerability allows for unauthorized file deletions, potentially disrupting user conversations or workflows that rely on the affected files.

Remediation

Users can upgrade to Concrete CMS version 9.5.1 or later, where this vulnerability has been fixed.

Added: May 21, 2026, 10:42 PM
Updated: May 21, 2026, 10:42 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.6
exploitability
6.4
remediation
7.7
relevance
9.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.