Impact
Concrete CMS 9.0.0 through 9.5.3 does not neutralize custom page alias names. The Edit Alias dialog only trims input, so an authenticated editor can store a malicious alias. When this alias is rendered in the administrative Sitemap panel, the script executes automatically in any administrator or editor session that opens the panel, enabling an editor to elevate privileges to administrator within the victim’s active session.
Affected Systems
All installations of Concrete CMS from version 9.0.0 up to and including 9.5.3 are affected. The vulnerability applies to any site where users can edit page aliases and are granted canWrite permission on a page.
Risk and Exploitability
The CVSS v4.0 score of 7.3 indicates a high impact. While no EPSS score is available, the attack can be performed by any authenticated user with editors’ rights, making exploitation likely in environments where such permissions are broadly granted. The vulnerability is not listed in CISA KEV, but because it enables direct privilege escalation through a stored XSS vector, it remains a serious concern for administrators of affected sites.
OpenCVE Enrichment