Impact
Concrete CMS versions between 9.0.0 and 9.5.2 omitted a block‑level permission check for the Express Form block’s control‑management operations. The controls’ actions are protected only by a CSRF token that is tied to the user and the specific action, not to the particular block, page or form. Consequently, an authenticated editor who has edit rights on one Express Form can reuse a valid CSRF token to add, modify or delete controls on other Express Forms for which they lack permission. By inserting a control whose value is rendered as raw HTML, the attacker can persist a cross‑site‑Scripting payload that will be executed whenever the form is processed or displayed. The weakness is an instance of unauthorized access to privileged capabilities (CWE‑862).
Affected Systems
The vulnerability affects Concrete CMS installations running versions 9.0.0 through 9.5.2. The problem is confined to the Express Form block functionality; any other components of the CMS are not directly impacted by the missing authorization check.
Risk and Exploitability
The CVSS v4 score of 2.0 indicates a low base severity, largely because an attacker must already possess a legitimate editor account. The EPSS probability of less than 1% suggests rare exploitation at the moment, and the vulnerability is not listed in the CISA KEV catalog. However, an attacker who can obtain or guess a valid editor’s CSRF token can elect to patch or modify the form’s controls remotely. Effective compromise requires accurate knowledge of the token, meaning the threat is primarily screen where the attacker can influence a logged‑in user or exploit session fixation. The absence of a hard block‑level check makes the vulnerability viable in scenarios where cross‑site request forgery is possible. Thus, while the risk rating remains low, any organizations using the affected CMS versions should still treat it as a risk that warrants remediation.
OpenCVE Enrichment