Impact
Concrete CMS versions 9.0.0 through 9.5.2 are vulnerable to a server‑side request forgery (CWE‑918) that exploits cross‑port reuse of a host’s validated DNS pin during remote file import. The flaw allows a low‑privileged authenticated user to supply a DNS rebinding host that resolves to a public address during validation and to a private or loopback address during the actual download. The CMS then fetches and stores the private resources, such as internal admin panels or cloud metadata endpoints, into the file manager, exposing sensitive internal data to the attacker. The impact is limited to data exfiltration and unauthorized visibility of internal resources, not direct code execution.
Affected Systems
The affected vendor is Concrete CMS. Versions impacted are 9.0.0 up to and including 9.5.2. No additional version details are provided.
Risk and Exploitability
The CVSS score of 2.1 indicates low severity, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be an authenticated remote file import request originating from a user with limited privileges. Successful exploitation requires the attacker to control the DNS resolution of a host used in multiple import URLs, enabling the server to download internal resources hidden behind different ports. No known public exploits have been reported.
OpenCVE Enrichment