Impact
Concrete CMS versions 9.5.0 through 9.5.2 contain an Open Redirect flaw enabled by the rcURL parameter. When a user follows a link on the site’s own domain that includes this parameter, the application redirects the browser to an arbitrary external site immediately after authentication or registration. The consequence is phishing and credential theft, as the attacker can lure users to malicious sites that mimic legitimate ones. The vulnerability is a classic example of CWE‑601, which represents insecure redirects that can be abused for social engineering attacks.
Affected Systems
All installations of Concrete CMS running any of the following versions are affected: 9.5.0, 9.5.1, and 9.5.2. Versions prior to 9.5.0 do not expose the rcURL parameter and therefore are not vulnerable. The flaw occurs in both the authentication and registration flows, providing two potential entry points on sites that allow user registration.
Risk and Exploitability
The CVSS v4.0 score of 5.3 indicates moderate severity. The EPSS score of < 1% shows that the likelihood of exploitation is very low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be user‐click; an attacker must craft a malicious link on the vulnerable site, and a victim must click that link, typically after login or registration, for the redirect to occur. No privilege escalation or remote code execution is required, but the social engineering impact can be significant if the victim is tricked into entering credentials at the target site.
OpenCVE Enrichment