Impact
Concrete CMS versions before 9.5.3 did not enforce a per‑page authorization check when reordering pages from the sitemap. A generic sitemap‑access check allowed an authenticated user who could reach the sitemap interface to move any page regardless of whether the user had Arrange or Edit rights on that page. This could be used to alter the site’s global navigation order. The flaw is categorized as Missing Authorization (CWE‑862).
Affected Systems
All installations of Concrete CMS running a version earlier than 9.5.3 are affected. The vulnerability has no specific version range beyond the stated cutoff, so any Concrete CMS instance prior to the 9.5.3 release is at risk.
Risk and Exploitability
The vulnerability is exploitable when an authenticated user can access the sitemap page; no elevated privileges are required. The CVSS score of 2.1 reflects its low severity. The EPSS score of 0.00229 indicates a very low, but non‑zero, probability of exploitation, and the vulnerability is not listed in CISA KEV. Because the flaw permits unauthorized manipulation of site navigation, it should be remediated promptly.
OpenCVE Enrichment