Impact
Concrete CMS 9 versions prior to 9.5.3 fail to escape SQL LIKE wildcard characters in the keyword search filters used by the file manager, file folders, and page list. An authenticated user with editor‑level or higher privileges can submit a query containing many single‑character wildcards, causing the database to perform full‑table scans that consume excessive CPU and I/O resources. The resulting performance degradation manifests as sluggish responsiveness for other users, leading to a denial‑of‑service condition for the site on large installations.
Affected Systems
The affected product is Concrete CMS 9, specifically the file manager, file folders, and page list features. This vulnerability applies to any installation running a Concrete CMS 9 release before 9.5.3, regardless of custom extensions or plugins that may interact with these modules.
Risk and Exploitability
The CVSS v4.0 score of 2.1 indicates a low‑ score is not available; the vulnerability is not listed in the CISA KEV catalog. Attackers need authenticated access with editor or higher rights, which is a typical internal or user‑level privilege. While the attack path is straightforward—crafting wildcard‑heavy search queries—the effect is limited to resource exhaustion and does not expose data or compromise control flow. Consequently, the overall risk is moderate, especially for large deployments where database load fluctuations are more noticeable.
OpenCVE Enrichment