Concrete CMS
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*
- <= 9.5.0
An Insecure Direct Object Reference (IDOR) vulnerability has been identified in Concrete CMS versions through 9.5.0. The issue arises in the '/ccm/frontend/conversations/get_rating' endpoint, which allows users to confirm the existence of messages and retrieve their rating scores by message ID. This vulnerability could be exploited to access and manipulate conversation ratings without proper authorization.
Exploitation of this vulnerability allows for unauthorized access to conversation ratings, potentially leading to manipulation of rating scores.
Users can upgrade to Concrete CMS version 9.5.1 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.