Impact
A missing authorization check in the Concrete CMS Express REST API list endpoint allows an attacker in possession of an OAuth token with read scope to enumerate Express entries that the token’s user should not be able to view. The flaw discloses each entry’s public identifier, URL, label, dates, and any attributes or associated-entry data requested via the includes parameter, thereby leaking sensitive or private content. This is an information‑disclosure vulnerability caused by the absence of per‑entry view permission checks.
Affected Systems
Concrete CMS versions 9.2.0 through 9.5.2 are affected. The issue resides in the Express REST API and applies to installations that expose the /Express endpoint and use Express entity.
Risk and Exploitability
The CVSS v4.0 score of EPSS score of less than 1 % shows a low probability of exploitation. The vulnerability is not in the CISA KEV catalog. Remote exploitation is possible over the network through the public REST API, but requires a valid OAuth token with read scope issued to a user. An attacker could enumerate restricted entries and retrieve potentially confidential data.
OpenCVE Enrichment