Impact
Concrete CMS versions 9 through 9.5.2 contain a missing authorization flaw in the block alias endpoint. The code does not confirm that the target block is truly orphaned or that the caller has permission over the source block. An editor who can add blocks to their own page can repeatedly submit any block ID on the site; the system copies that block's content into the editor's area, revealing potentially sensitive data, and then force‑deletes the original block in the same HTTP request, destroying site content before any operation integrity compromise, and causing availability loss for arbitrary site blocks.
Affected Systems
Vulnerable systems are all installations of Concrete CMS running version 9 up to and including 9.5.2, as only those versions are impacted.
Risk and Exploitability
The CVSS score of 5.9 reflects a moderate severity with an attack vector reachable over the network, low authentication effort, and no user interaction. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The attacker must be an authenticated editorial user with add‑block‑to‑area rights on their own page, a relatively small privilege set. Because the flaw exists in the public web interface, there is no exploitation threshold beyond normal editorial access. Exploitation would involve the attacker submitting the block ID, duplicating the block into the editor's area, and deleting the source block in the same request. No publicly available exploit scripts are known, and the flaw is not listed in CISA KEV; confidentiality impact is low while integrity and availability impacts are high.
OpenCVE Enrichment