Concrete CMS
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*
- <= 9.5.0
An Insecure Direct Object Reference (IDOR) vulnerability has been identified in Concrete CMS versions 9.5.0 and prior. The issue arises in the '/ccm/frontend/conversations/message_detail' endpoint, which exposes the full content of any conversation message to unauthenticated users. This vulnerability allows enumeration of all conversation messages, including those from restricted pages, member-only areas, and the moderation queue. Additionally, file attachments with download URLs are also disclosed.
Exploitation of this vulnerability allows unauthorized access to private conversation messages and associated file attachments, including download links.
Users can upgrade to Concrete CMS version 9.5.1 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.