Impact
Concrete CMS version 9.2.0 to 9.5.2 features a missing authorization check in its REST API that allows an authenticated user with the groups:read scope to the full list of groups via the GET /ccm/api/1.0/groups endpoint. The flaw stems from the listGroups() method in concrete/src/Api/Controller/Groups.php, where a permissions checker callback unconditionally returns true, bypassing per‑object view checks. This results in the disclosure of the site’s entire group structure, roles and access hierarchy, representing a moderate severity information‑disclosure vulnerability. This missing authorization weakness is a CWE-862 flaw.
Affected Systems
Concrete CMS 9.2.0 through 9.5.2, with the vulnerability present in concrete/src/Api/Controller/Groups.php.
Risk and Exploitability
The CVSS score of 6.0 indicates a moderate severity vulnerability while the EPSS score of less than 1% reflects a low probability of exploitation. Concrete CMS is not listed in the CISA KEV catalog, and no public exploit is known. An attacker that possesses an authenticated API token with the groups:read scope can call the vulnerable endpoint, gather a comprehensive list of groups, and use that information for planning social engineering or privilege‑escalation attacks. The attack requires only an authenticated session; no special privileges are needed beyond the standard API permissions.
OpenCVE Enrichment