Impact
Concrete CMS versions 9.0.0 through 9.5.2 have a missing authorization check on the /ccm/system/user/autocomplete endpoint, which is used by user selector components such as Preview as User. This defect corresponds to CWE-862: Missing Authorization Check. The endpoint only verifies a CSRF‑style token that is granted to anonymous visitors, and this token is not tied to the requester's identity or privileges. When an attacker submits an empty query, the endpoint returns all backend user records, revealing internal user IDs, usernames and email addresses. Password hashes or session data are not disclosed, but the exposed account information can be leveraged for further attacks.
Affected Systems
Concrete CMS, versions 9.0.0 through 9.5.2 The vulnerability spans all builds within this version range and applies to any installation that has not yet applied the missing authorization guard to the autocomplete API.
Risk and Exploitability
The CVSS score of 8.7 reflects high impact with low effort to exploit. The vulnerability does not need any special privileges or authentication; an unauthenticated user who can reach the CMS instance can send a request to /ccm/system/user/autocomplete, submit an empty search, and paginate to enumerate every administrative account. The EPSS score of < 1% indicates a very low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The abuse potential is significant for unpatched installations because the returned data includes all administrator identifiers, which can facilitate credential‑guessing or other malicious actions.
OpenCVE Enrichment