Impact
Concrete CMS versions earlier than 9.5.3 do not verify the anti‑CSRF token for the save_control action in the Express entities dashboard. An attacker can cause an authenticated administrator to submit a forged request that writes attacker‑controlled markup into the headline and body fields of an existing Express form Text control. These fields are rendered without output encoding, so the embedded script runs as persistent JavaScript whenever any administrator opens the affected entry.
Affected Systems
Concrete CMS installations running any version below 9.5.3 are affected. The flaw resides in the Express form Text control within the Express entities module and requires that the target system host this module.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity, reflecting a significant threat if a malicious script is executed by an administrator. The EPSS score is under 1 %, suggesting a low likelihood of exploitation in the wild at present, but the vulnerability is not listed in CISA’s KEV catalog. An attacker can achieve this via a web‑based CSRF attack, requiring an authenticated administrator to submit the forged request.
OpenCVE Enrichment