Concrete CMS Cross-Site Request Forgery Vulnerability Allowing Remote Code Execution

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Concrete CMS versions 9.5.0 and below. The issue resides in the 'install_package()' method of 'concrete/controllers/single_page/dashboard/extend/install.php'. An attacker can exploit this vulnerability by causing an authenticated administrator to visit a malicious page while a targeted package is placed under 'DIR_PACKAGES/<handle>/'. This exploitation can lead to unauthorized package installation, executed as the web server user, thereby enabling remote code execution. The vulnerability is present when the victim has the 'canInstallPackages' permission.

Impact

Exploitation of this vulnerability allows for Cross-Site Request Forgery, leading to unauthorized package installation and potential remote code execution on the server.

Added: May 21, 2026, 9:21 PM
Updated: May 21, 2026, 9:21 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
7.5
exploitability
6.2
remediation
7.7
relevance
9.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.