Impact
Concrete CMS 9 versions before 9.5.3 fail to escape SQL LIKE wildcard characters in the keyword search filters used by the file manager, file folders, and page list. An authenticated user with editor‑level or higher privileges can submit a query containing many single‑character wildcards, causing the database to perform full‑table scans that consume excessive CPU and I/O resources. The resulting performance degradation manifests as sluggish responsiveness for other users, leading to a denial‑of‑service condition for the site on large installations.
Affected Systems
The affected product is Concrete CMS 9, specifically the file manager, file folders, and page list features. This vulnerability applies to any installation running a version earlier than 9.5.3, regardless of custom extensions or plugins that may interact with these modules.
Risk and Exploitability
The CV.1 indicates a low‑impact vulnerability. The EPSS score is less than 1%, showing a very low probability of exploitation in the wild. Attackers need authenticated access with editor or higher privileges, which is typically available to internal users. The attack path is straightforward: crafting wildcard‑heavy search queries forces full‑table scans that consume excessive CPU and I/O. The effect is limited to resource exhaustion and does not expose data or compromise control flow. Consequently, the overall risk is moderate, especially for large.
OpenCVE Enrichment