Concrete CMS IDOR Vulnerability in Conversations Message Detail Endpoint

Vulnerability

An Insecure Direct Object Reference (IDOR) vulnerability has been identified in Concrete CMS versions 9.5.0 and prior. The issue arises in the '/ccm/frontend/conversations/message_detail' endpoint, which exposes the full content of any conversation message to unauthenticated users. This vulnerability allows enumeration of all conversation messages, including those from restricted pages, member-only areas, and the moderation queue. Additionally, file attachments with download URLs are also disclosed.

Impact

Exploitation of this vulnerability allows unauthorized access to private conversation messages and associated file attachments, including download links.

Remediation

Users can upgrade to Concrete CMS version 9.5.1 to address this vulnerability.

Added: May 21, 2026, 10:35 PM
Updated: May 21, 2026, 10:35 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
2.5
exploitability
6.8
remediation
7.7
relevance
9.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.