Impact
Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry submission against the entity of the posted form rather than the entity identified by the dashboard route. As a result, a user permitted to add entries to one Express object could create entries in a different Express object outside their authorization scope, potentially polluting protected datasets, triggering workflows, or injecting content into administrative processes.
Affected Systems
All Concrete CMS installations running any version earlier than 9.5.3 are affected. The vulnerability impacts the Express Entries Dashboard feature and applies to any Express objects configured within the system, regardless of the specific schema or permissions applied.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity flaw that can be leveraged remotely by an authenticated user with high privileges, as reflected in the attack vector and privilege requirements. The EPSS score is < 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because the exploit requires a valid user session and the capability to craft a request to the vulnerable dashboard route, the primary attack path involves authenticated accesses to dashboard routes. The impact is limited to the unauthorized creation of entries, but the availability of complex workflows may amplify downstream consequences. Overall, the risk is moderate yet actionable, especially for systems that expose Express entry dashboards to users with elevated permissions.
OpenCVE Enrichment