Impact
Concrete CMS versions 9.2.0 through 9.5.2 contain a missing authorization check in the Area REST API block‑create endpoint. When a block that references files—such as hero_image or gallery—is created, the block type controller’s validate() method, which normally verifies that the user is permitted to reference the selected file, is not invoked. This omission allows an authenticated user with block‑add scope to store and cause a page to render a reference to a file that the file‑manager visibility policy would otherwise reject, thereby disclosing the file’s URL and preview. The weakness corresponds to CWE‑862: Missing Authorization.
Affected Systems
Concrete CMS, versions 9.2.0 through 9.5.2
Risk and Exploitability
The vulnerability has a CVSS v4.0 score of 5.1, indicating moderate severity. The EPSS score is less than 1 percent, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated user who possesses block‑add scope, the attacker can obtain the file URL and preview, exposing files the user otherwise could not access.
OpenCVE Enrichment