Description
In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] without validating them as integers, and when the block was configured with setMode set to any it concatenated each stored identifier directly into the file-set filter query instead of casting it or binding it as a parameter. An authenticated user permitted to add or edit a Document Library block could therefore persist SQL syntax in the block configuration (btDocumentLibrary.setIds), and that stored expression was executed every time the published page containing the block was rendered, producing stored, time-based blind SQL injection. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 8.5 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Habib Allah for reporting.
Published: 2026-09-15
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored SQL injection allowing an authenticated user to execute arbitrary database queries
Action: Apply Patch
AI Analysis

Impact

Concrete CMS before version 9.5.3 stored file‑set identifiers from the fsID[] parameter without validating them as integers. When the Document Library block was configured with setMode set to any, the system concatenated each stored identifier directly into the file‑set filter query. An authenticated user who could add or edit the block could persist malicious SQL syntax in the block configuration, causing that expression to run on every rendered page and resulting in stored, time‑based blind SQL injection. The vulnerability carries a CVSS v4.0 score of 8.5, indicating a high impact on the confidentiality, integrity and availability of the database.

Affected Systems

Concrete CMS Document Library block in Concrete CMS 9.5.2 and earlier versions is affected. The specific vulnerability involves the configuration settings of the block that allow unauthenticated integer validation. Users running any Concrete CMS installation on those legacy versions should review their Document Library block configuration.

Risk and Exploitability

The CVSS vector reflects an accessible network attack with low complexity, no user interaction, and a high risk privilege level that can compromise the database. The EPSS score is < 1%, indicating a very low current exploitation probability, though the lack of a KEV listing does not diminish the risk for organizations that still host the vulnerable versions. The likely attack vector requires the attacker to have permissions to add or edit a Document Library block; once in place, the stored injection executes during normal page rendering, allowing an attacker to extract, modify, or delete data from the CMS database.

Generated by OpenCVE AI on September 20, 2026 at 15:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.3 or newer, where the input from fsID[] is validated and bound as a parameter.
  • If an upgrade is not immediately possible, restrict or remove permissions for untrusted users to add or edit Document Library blocks so that the vulnerable configuration cannot be saved.
  • After restricting permissions, verify that no existing Document Library blocks contain saved ids that could be interpreted as SQL; if they do, manually remove or correct them before rendering pages.

Generated by OpenCVE AI on September 20, 2026 at 15:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Tue, 15 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] without validating them as integers, and when the block was configured with setMode set to any it concatenated each stored identifier directly into the file-set filter query instead of casting it or binding it as a parameter. An authenticated user permitted to add or edit a Document Library block could therefore persist SQL syntax in the block configuration (btDocumentLibrary.setIds), and that stored expression was executed every time the published page containing the block was rendered, producing stored, time-based blind SQL injection. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 8.5 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Habib Allah for reporting.
Title Concrete CMS 9.5.2 and below is vulnerable to Stored SQL Injection in Concrete CMS Document Library Block via `fsID[]` in `setMode=any`
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-22T18:09:47.853Z

Reserved: 2026-08-27T18:18:39.737Z

Link: CVE-2026-81895

cve-icon Vulnrichment

Updated: 2026-09-22T18:09:38.546Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T17:17:27.710

Modified: 2026-09-22T19:16:52.503

Link: CVE-2026-81895

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:30:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')