Impact
Concrete CMS versions prior to 9.5.3 allow an attacker to bypass deactivated or email‑unvalidated account checks so that a user who already has an OAuth binding can complete authentication and receive a fully authenticated session, even though the account is disabled or its email address has not been verified. This creates an authorization bypass that can be exploited to gain unauthorized access to the site as that user, exposing any data or permissions the account holds.
Affected Systems
The vulnerability affects Concrete CMS products that have not applied the 9.5.3 release or later. Specifically, Concrete CMS versions earlier than 9.5.3 lack the necessary check for an account’s active status or email validation when processing OAuth callbacks.
Risk and Exploitability
The issue has a CVSS v4.0 score of 6.3, indicating moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be through the public OAuth callback endpoint, requiring an existing OAuth binding for an interaction beyond initiating the OAuth flow, and no privileged access is needed beyond the binding premise. The exploitation conditions suggest a realistic possibility of misuse if an attacker can identify or create such bindings.
OpenCVE Enrichment