Concrete CMS
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*
- <= 9.5.0
A vulnerability exists in Concrete CMS versions through 9.5.0, where missing authorization in the bulk user assignment dashboard can lead to privilege escalation by allowing any authenticated user to manipulate group assignments. This includes adding users to any group or removing legitimate administrators. The issue arises from inadequate authorization checks in the 'bulk_user_assignment.php' file, enabling unauthorized changes to user group memberships.
Exploitation of this vulnerability could result in unauthorized users being granted administrative privileges or legitimate admins being removed from their roles.
Users can upgrade to Concrete CMS version 9.5.1 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.