Impact
Concrete CMS versions below 9.5.3 have a CSRF vulnerability in the Dashboard SEO Excluded Words Reset endpoint. The reset action clears the administrator‑configured reserved‑word list without validating the CSRF token or restricting the request to the POST method. An attacker can lure an authenticated user with SEO privileges to a crafted page, causing the site to revert its reserved‑word list to default values and silently change how slugs are generated for pages, files and other objects. This undermines the site’s configured SEO slug policy and can break URLs and damage search engine rankings.
Affected Systems
All installations of Concrete CMS running a version earlier than 9.5.3 are affected. The vulnerability occurs on the Concrete CMS dashboard under the SEO management area.
Risk and Exploitability
The CVSS v4.0 score of 2.3 indicates low severity; the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web‑based CSRF attack that requires an attacker to trick a legitimate authenticated user to trigger the reset. Because the attack requires an authenticated session with SEO access, the risk to an unauthenticated attacker is low, but any impacted site’s SEO and URL scheme integrity could be compromised.
OpenCVE Enrichment