Impact
Concrete CMS versions before 9.5.3 are vulnerable to a Cross‑Site Request Forgery flaw in the Move Multiple Groups feature. The dashboard/users/groups/bulkupdate/confirm() endpoint accepts a group move request without validating an action token. An attacker request that a logged‑in user unknow to be relocated under a new parent. Because child groups inherit the new parent’s permissions, this move can effectively alter the authorization for all users in those groups.
Affected Systems
Concrete CMS installations running any version earlier than 9.5.3 are affected. The flaw resides in the Move Multiple Groups functionality accessed via the dashboard users groups bulk update confirmation endpoint.
Risk and Exploitability
The CVSS v4.0 score of 5.7 reflects moderate severity. The flaw requires an authenticated user session and a simple HTTP request; it is a classic CSRF misuse. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would likely embed a malicious request in a thirding the user’s browser into moving group nodes and thereby changing group permissions without authorization.
OpenCVE Enrichment