Impact
Concrete CMS versions earlier than 9.5.3 allow a crafted request that does not require a valid anti-CSRF token to rearrange or move blocks within the draft version of a page. This flaw enables the attacker to exploit an authenticated editor’s session, causing the block arrangement to be altered without the editor’s consent. The vulnerability stems from missing CSRF validation, categorized as CWE-352.
Affected Systems
All installations of Concrete CMS running any release below 9.5.3 are vulnerable. The issue targets the block-arrangement backend endpoint in the arrange() action of Concrete\\Controller\\Backend\\Page\\ArrangeBlocks.
Risk and Exploitability
The flaw has a CVSS v4.0 score of 2.3, indicating low severity. The EPSS score is 0.00165, reflecting a very low likelihood of exploitation. It is not listed in the CISA KEV catalog. Exploitation requires a logged‑in content editor, a website that accepts the attacker’s manipulated request, and the default null SameSite cookie setting that allows the victim’s session cookie to be sent. The attacker can induce the editor to perform the action by loading a malicious page that auto‑submits a request, thereby moving or reordering blocks on a draft page.
OpenCVE Enrichment