Impact
Concrete CMS versions earlier than 9.5.3 contain a missing authorization check that allows files to be stored in the file manager before verifying that the user has the "Add Message Attachments" permission. This flaw permits the upload of approved file types without proper authorization, leading to an unauthorized file import into the CMS’s backend. The vulnerability, defined under CWE‑862 (Missing Authorization), can enable an attacker to introduce files that may be used for data exposure, further exploitation, or persistence within the CMS. The description explicitly states that the permission is only checked after the file is stored, and the CMS security team rated the issue with a low CVSS v4.0 score of 2.3.
Affected Systems
The flaw applies to all Concrete CMS deployments running a version older than 9.5.3. Environments configured to allow guest posting are especially affected because the upload endpoint can be accessed without authentication. Upgrading to version 9.5.3 or later removes the flaw and enforces the permission check before any file is accepted.
Risk and Exploitability
The CVSS v4.0 score of 2.3 indicates a low severity impact, and the EPSS score of <1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could reach the upload endpoint over the network, possibly without authentication in guest‑posting settings, and could potentially upload arbitrary files of allowed types. The low attack complexity and low privileged requirement (just lack of the Add Message Attachments permission) mean that exploitation would require minimal effort, but the risk remains moderate in guest‑posting configurations due to the lack of initial authentication.
OpenCVE Enrichment