Concrete CMS
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*
- <= 9.5.0
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Concrete CMS versions through 9.5.0. The issue arises from an inverted CSRF token validation in the DeleteFile controller, where the system erroneously processes file deletions when the token is invalid or absent. This flaw effectively nullifies CSRF protection for the file deletion endpoint, enabling unauthorized file deletions by exploiting users' permissions to edit conversation messages.
Exploitation of this vulnerability allows for unauthorized file deletions, potentially disrupting user conversations or workflows that rely on the affected files.
Users can upgrade to Concrete CMS version 9.5.1 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.