Impact
This vulnerability is caused by the Express Clear Entries controller not enforcing a CSRF token check, allowing a malicious request to delete all records of request even if the CSRF token is missing or invalid, enabling mass data loss. An attacker can force a logged‑in administrator to visit an attacker‑controlled page to trigger the destructive operation, permanently removing all entries belonging to the specified entity, including default objects with fixed UUIDs that can be discovered without dashboard access.
Affected Systems
Concrete CMS versions 9.5.2 and earlier are affected. Administrators using these versions are at (POST /index.php/dashboard/system/express/entities/delete_entries) is exposed and not properly protected.
Risk and Exploitability
The CVSS V4.0 score of 6.1 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, a remote unauthenticated attacker can trigger the flaw logged‑in administrator to load the delete_entries endpoint without a valid CSRF token. This can permanently erase all entries for any Express entity, causing significant loss of data for the compromised site.
OpenCVE Enrichment