Impact
The vulnerability allows a user with content‑editing rights to modify page properties, templates, and types through the REST API endpoint PUT /ccm/api/1.0/pages/{cID}. Because the endpoint does not enforce authorization on the header_extra_content field, an attacker can persist malicious JavaScript into the head of every page. This JavaScript is rendered unescaped, giving the attacker a stored cross‑site scripting weakness that affects all visitors, including administrators who approve page versions.
Affected Systems
Concrete CMS installations running version 9.2.0 up to and including 9.5.2 are affected. These are the only versions documented as vulnerable; newer releases are not impacted.
Risk and Exploitability
The CVSS score of 7.2 indicates a medium‑to‑high severity. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, but the REST API is exposed over HTTP(S) so an attacker who can authenticate with a content‑editing account could reach the vulnerable endpoint. This is the inferred attack vector. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment