Impact
Concrete CMS before version 9.5.3 contained a legacy Express entry search endpoint that returned full entry result JSON without performing the standard canViewExpressEntries() permission check. This omission allowed an unauthenticated visitor who could guess or learn an Express entity identifier to retrieve sensitive attribute values that should have been restricted to privileged users. The flaw is a classic missing authorization weakness, classified as CWE‑862.
Affected Systems
The vulnerability affects installations of Concrete CMS, Concrete CMS 9.x, that have not been updated to version 9.5.3 or later. Only those versions that retain the legacy Express search API are impacted.
Risk and Exploitability
The CVSS v4.0 score of 6.3 indicates a moderate severity, while the EPSS score of less than 1 % points to a very low likelihood of exploitation today. The flaw is not listed in the CISA KEV catalog. Exploitation requires remote access to the application, knowledge or guess of an Express entity identifier, and does not require authentication. Once accessed, an attacker can enumerate the entry search results for that entity, potentially disclosing confidential data.
OpenCVE Enrichment