Impact
Concrete CMS versions 9.0.0 through 9.5.2 permit the storage of unescaped group folder names. A malicious payload can be persisted and rendered as active HTML on the Members > Groups dashboard. When an administrator views the page, the script executes inside the administrator’s browser session, enabling theft of session cookies, tokens, and the ability to perform any administrative operation.
Affected Systems
Concrete CMS 9.0.0 up to and including 9.5.2 are affected. The flaw can be triggered by any authenticated user who possesses the Add Group Folder permission, allowing the attacker to store a malicious folder name that will be displayed on the group dashboard for all administrators.
Risk and Exploitability
The CVSS v4.0 score of 7.3 denotes a high‑severity vulnerability. The EPSS score is 0.00274, indicating a low but non‑zero likelihood of exploitation, and the issue is not listed in CISA KEV. Exploitation requires an authenticated user with Add Group Folder privileges; the attacker can then inject a script that runs when any administrator opens the Groups dashboard. The attack complexity is low, the required privileges are high, and user interaction is needed only from the victim administrator, who will inadvertently execute the malicious code in their session.
OpenCVE Enrichment