Impact
Concrete CMS versions 8.3.0 through 9.5.2 contain an authorization bypass flaw in the Calendar event edit dialog. The dialog uses a user supplied calendar identifier instead of the calendar that owns the targeted event, allowing a user who has the basic "Add Event" permission on one calendar to see, modify, or delete events on other calendars they should not be able to access. This violates expected authorization boundaries and can lead to unauthorized disclosure or tampering of calendar data, as well as disruption of scheduled events.
Affected Systems
The vulnerability affects Concrete CMS installations running any software version from 8.3.0 up to and including 9.5.2. No earlier or later releases are identified as vulnerable.
Risk and Exploitability
With a CVSS score of 5.9 and a vector indicating a network attack with low complexity and high required privileges, the threat is moderate. The exploit requires permission on a calendar; such a user can then access the edit dialog and supply a different calendar ID to manipulate events elsewhere. No public exploits are currently documented and the EPSS score is unavailable, but the vulnerability is listed in the vendor’s documentation and should be considered mitigable through a patch, rather than relying on workarounds.
OpenCVE Enrichment