Impact
Concrete CMS versions 9.5.2 and earlier allow unauthorized disclosure of calendar event metadata when an attacker supplies a forged /ccm/calendar/view_event/{bID}/{occurrence_id} URL. The endpoint loads an event occurrence without verifying that the occurrence belongs to the configured calendar block, enabling extraction of the event title, date, description, page link, and custom attributes.
Affected Systems
Concrete CMS as delivered by the Concrete CMS vendor, specifically all releases 9.5.2 and earlier.
Risk and Exploitability
The CVSS v4.0 score of 6.3 indicates a medium severity vulnerability, and the EPSS score is not available, suggesting no current data on exploitation probability. The endpoint is publicly reachable from any browser that can render a calendar block with lightbox enabled, so an unauthenticated attacker who can view a public calendar can supply arbitrary occurrence identifiers. The vulnerability is not listed in the CISA KEV catalog, but it remains an actionable risk as it permits disclosure of non‑sensitive event data and may be leveraged for reconnaissance.
OpenCVE Enrichment