Impact
Concrete CMS versions 9 through 9.5.2 contain a missing authorization check in the Boards data source dashboard controller for_data ConfiguredDataSource based on an attacker‑supplied identifier without verifying that the requester has edit permission on the owning board. The CSRF token is validated but is bound only to the action name rather than obtained for one board to be replayed against another. As a result, a user with the edit_board_settings role on a single board can modify or permanently delete the configured data sources of any other board on the site, effectively halting that board’s content feed and resetting its custom weighting. This flaw primarily undermines integrity and can degrade availability of board content.
Affected Systems
The vulnerability applies to Concrete CMS 9.0.0 through 9.5.2, affecting all installations that use the Boards data source dashboard. The flaw permits a low‑privileged board editor with edit_board_settings permission to act on any board’s data source configuration.
Risk and Exploitability
The CVSS base score of 2.1 indicates low severity. The EPSS score of <1% suggests a very low probability of exploitation. The vulnerability is not listed in CISA KEV. Exploitation requires an authenticated user with edit_board_settings rights. Given these metrics, the overall risk is low.
OpenCVE Enrichment