Impact
Concrete CMS versions 9.0.0 through 9.5.2 allow a remote unauthenticated attacker to delete a custom group type because the dashboard delete action does not validate a CSRF token. The attacker can trigger the deletion via a crafted link or form presented to an authenticated user with group‑type‑management permission. The exploit does not provide direct access to other data, but it compromises the site’s configuration and organization by removing a group type that may be used for access control or content association.
Affected Systems
Concrete CMS instances running any version from 9.0.0 up to and including 9.5.2 are affected. The vulnerability exists in the CMS platform’s dashboard group‑type controller and applies to any installation where group‑type‑management roles are granted.
Risk and Exploitability
The CVSS v4.0 score of 2.3 indicates a low severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation. The attack requires that the victim be logged into the CMS with appropriate permissions and that the attacker can reach the dashboard endpoint, so the conditions are limited. This vulnerability is not listed in the CISA KEV catalog, implying it has not been widely exploited in the wild. The likely attack vector is a remote unprivileged actor sending a CSRF request to an authenticated user; this vector is inferred from the description and the absence of explicit mention of authentication requirements.
OpenCVE Enrichment