Impact
Concrete CMS versions 9.0.0 through 9.5.2 contain a Cross‑Site Request Forgery vulnerability in the orphan block cleanup action. An attacker can craft a request that, when executed by an authenticated user with edit permission on its current version, removes every block on that page's current version; blocks not aliased to another page or scrapbook entry are also removed from the global Blocks table and their block‑type data table, permanently destroying the content. The vulnerability is a type of CSRF (CWE‑352) that results in data destruction without the need for code execution.
Affected Systems
Concrete CMS versions 9.0.0 through 9.5.2 are affected. No sub‑products or additional versions were identified in the advisory.
Risk and Exploitability
The CVE is scored 7.1 on CVSS‑high severity, and the EPSS score is <1%, indicating a very low likelihood of exploitation; it is not listed in CISA’s KEV catalog. The attack requires the victim to be an authenticated user with edit rights to the target page and the attacker to persuade that user to load a specially crafted request. This describes a classic CSRF scenario reflected in the UI:P vector component. Given the high CVSS score and the very low exploitability metric, the likelihood of exploitation is low, but the impact of content loss warrants a prompt response.
OpenCVE Enrichment