Impact
Concrete CMS versions before 9.5.3 contain a Cross‑Site Request Forgery flaw in the Dashboard SEO Excluded Words Reset endpoint. The reset action clears the admin‑configured list of reserved words without validating the anti‑CSRF token or limiting the request to the POST method, as described by the CWEs. An attacker who lures an authenticated user with SEO privileges to a crafted page can force the site to restore the default excluded word list, silently modifying how URL slugs are generated for pages, files, topics, and other objects. This change undermines the site’s SEO policy and can cause broken URLs or degraded search engine rankings. The abuse does not disclose or modify data directly, but it alters critical site configuration.
Affected Systems
Affected systems include all installations of Concrete CMS running a version earlier than 9.5.3. The vulnerability is present on the dashboard under the SEO management section and requires the target user to have administrative access to the SEO module. Vendor descriptions state the fix is applied in version 9.5.3 and later.
Risk and Exploitability
The risk is low in terms of confidentiality, integrity, and availability as the CVSS v4.0 score is 2.3 and the EPSS score is below 1%. The flaw requires an attacker to trick an authenticated user, which limits the exposure to sites with many authenticated administrators or those with broad SEO access. The flaw is not listed in the CISA KEV catalog, and there are no known public exploits as of the latest data. Nevertheless, a CSRF attack can still disrupt search engine optimization, so remediation is advisable.
OpenCVE Enrichment