Impact
Concrete CMS versions 9.0.0 through 9.5.2 allow a remote unauthenticated attacker to delete a custom group type by using a dashboard action that does not validate a CSRF token. The attacker can trigger the deletion through a crafted link or form directed at an authenticated user who has group‐type‑management permission. The exploit does not provide direct access to other data, but it compromises the configuration and organization of The CVSS v4.0 score of 2.3 indicates a low‑severity vulnerability.
Affected Systems
The flaw affects Concrete CMS releases 9.0.0 to 9.5.2. The affected product is the Concrete CMS CMS platform; any instance running a version in this range and configured with a group‑type‑management role is susceptible.
Risk and Exploitability
The overall risk is low as reflected by the CVSS score and the absence of an EPSS score, which means no publicly known exploitation activity has been reported. The attack requires that the victim be logged into the CMS with appropriate permissions and that the attacker be able to reach the dashboard endpoint, so the likelihood is moderate but constrained. The vulnerability is not listed in CISA’s KEV catalog, indicating it has not been widely exploited in the wild.
OpenCVE Enrichment