Impact
Concrete CMS versions 9.0.0 through 9.5.2 allow an authenticated user with broad sitemap access to reorder any page’s display order. The backend endpoint, SitemapUpdate::updateDisplayOrder, relies only on a global sitemap flag and skips checking each target page’s edit permissions. Additionally, the action omits a CSRF token, so a forged request can trigger the write. The result is that a user who cannot edit certain pages can still change the order in which those pages appear in navigation menus, breadcrumbs, and page‑list output, potentially misleading visitors or altering the perceived structure of the site. The vulnerability does not grant code execution or data exfiltration but does expose a flaw in access control semantics for page ordering.
Affected Systems
Any installation of Concrete CMS version 9.0.0 up to and including 9.5.2 that has enabled the dashboard sitemap functionality. All such sites must be evaluated for the presence of the vulnerable reorder endpoint.
Risk and Exploitability
The CVSS score of 2.1 indicates a low impact rating. The EPSS score is reported as below 1 %, meaning the exploitation probability is very low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with sitemap permission, so it is constrained to internal or compromised accounts. Because the lack of a CSRF token allows a forged request, an attacker who can trick the victim into accessing a crafted URL could trigger the action from a remote context, but still must possess the necessary permission. Given the limited scope and low likelihood, the overall risk is minimal, but the issue demonstrates a weakness in authorization checks that can be abused by privileged users.
OpenCVE Enrichment