Impact
Concrete CMS versions 9 through 9.5.2 contain a Server‑Side Template Injection flaw in the Theme Customizer. Style values entered through the customizer—such as color channels, font families, and image styles—are interpolated directly into server‑compiled LESS code without escaping or neutralization. An attacker who holds the Theme Customization permission can inject arbitrary LESS directives; for example, using the @import (inline) statement allows reading arbitrary files on the server and accessing internal network resources via PHP stream wrappers. The resulting compiled CSS is publicly cached, exposing the contents of any read files—including database credentials, private keys, and other secrets—through a site’s CSS cache, and it also enables server‑side request forgery.
Affected Systems
The affected product is Concrete CMS, specifically versions 9 through 9.5.2. The vulnerability involves the ColorStyle, FontFamilyStyle, ImageStyle, and related Style classes that process Theme Customizer input.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate risk, while an EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog, meaning no widespread attacks are documented. Exploitation requires Theme Customization privilege, typically limited to administrators or users with similar roles. Once an attacker injects malicious LESS, the server compiles the style and writes it to the public CSS cache, exposing any disclosed file contents and permitting server‑side request forgery. Although the exploitation likelihood is low, the potential impact on confidentiality is high, so organizations running vulnerable installations should prioritize remediation.
OpenCVE Enrichment