Impact
Concrete CMS before version 9.5.3 stored file‑set identifiers from the fsID[] parameter without validating them as integers. When the Document Library block was configured with setMode set to any, the system concatenated each stored identifier directly into the file‑set filter query. An authenticated user who could add or edit the block could persist malicious SQL syntax in the block configuration, causing that expression to run on every rendered page and resulting in stored, time‑based blind SQL injection. The vulnerability carries a CVSS v4.0 score of 8.5, indicating a high impact on the confidentiality, integrity and availability of the database.
Affected Systems
Concrete CMS Document Library block in Concrete CMS 9.5.2 and earlier versions is affected. The specific vulnerability involves the configuration settings of the block that allow unauthenticated integer validation. Users running any Concrete CMS installation on those legacy versions should review their Document Library block configuration.
Risk and Exploitability
The CVSS vector reflects an accessible network attack with low complexity, no user interaction, and a high risk privilege level that can compromise the database. The EPSS score is < 1%, indicating a very low current exploitation probability, though the lack of a KEV listing does not diminish the risk for organizations that still host the vulnerable versions. The likely attack vector requires the attacker to have permissions to add or edit a Document Library block; once in place, the stored injection executes during normal page rendering, allowing an attacker to extract, modify, or delete data from the CMS database.
OpenCVE Enrichment