Concrete CMS
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*
- <= 9.5.0
An authorization bypass vulnerability has been identified in the Calendar Block of Concrete CMS versions through 9.5.0. The issue arises because the 'action_get_events' function does not properly check the 'canView' permission on calendars. This oversight allows restricted event details to be disclosed.
Exploitation of this vulnerability leads to unauthorized disclosure of event details from private calendars.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.