Impact
Concrete CMS versions 9.0.0 through 9.5.2 allow an authenticated user to delete or rename Express saved search presets that belong to other entities. The vulnerability arises from insecure direct object reference, granting an attacker the ability to tamper with configuration data and display altered preset names to other users, which can be used for defacement or social engineering. This is a CWE‑639 vulnerability that affects the integrity of saved search data.
Affected Systems
The affected product is Concrete CMS by Concrete CMS, specifically versions 9.0.0 to 9.5.2 inclusive. Any deployments running within that version range are susceptible to the IDOR flaw in the Express saved search preset delete and edit dialogs.
Risk and Exploitability
The CVSS score of 2.1 indicates low overall severity, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation data. Because it requires an authenticated user with at least view permission on one Express entity, an attacker does not need elevated privileges. The flaw can be exploited by navigating to the Express preset interface and issuing delete or rename actions on preset identifiers that the user does not own, leading to permanent removal or misleading information presented to other users. The lack of an EPSS score means current prediction of exploitation probability is unavailable, but the low score and limited exposure reduce immediate risk to most installations.
OpenCVE Enrichment