Impact
Concrete CMS versions prior to 9.5.3 contain a cross‑site request forgery flaw in the Calendar event duplicate dialog controller, where the submit action fails to validate an anti‑CSRF token while only checking generic access permissions. This weakness, identified as CWE‑352, allows an attacker to craft a request that causes an authenticated user with add‑event rights to duplicate calendar events and event version records under the user’s own authority. The resulting damage is limited to the creation of duplicate entries; there is no escalation to higher privileges or arbitrary code execution.
Affected Systems
Any installation of the open‑source Concrete CMS platform running a version earlier than 9.5.3 is vulnerable. The flaw affects the Calendar event duplicate dialog controller in all pre‑9.5.3 releases, regardless of individual site configuration, as no further version granularity is specified.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, with network access, low complexity, and no user interaction required beyond a normal login. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a crafted CSRF request that a web browser loads while an authorized user with permission to add events is logged in, thereby causing the site to duplicate an existing event.
OpenCVE Enrichment