Impact
In Concrete CMS versions prior to 9.5.3 the SEO Bulk Update Meta Tags editor did not verify that a user had permission to edit page properties before saving changes. An attacker who could use the bulk SEO tool and view a page, but could not edit it, was able to alter the meta title, meta description, and URL handle of that page. This tampering changes the presentation and live URL of protected content.
Affected Systems
Concrete CMS concrete CMS versions earlier than 9.5.3. The vulnerability affects any installation where the bulk SEO tool is enabled and users have been granted bulk editing rights while lacking page edit permission.
Risk and Exploitability
The CVSS score of 2.1 indicates low severity. The EPSS score is <1% (approximately 0.23%), suggesting a very low likelihood of exploitation, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is an internal user who has access to the bulk SEO tool; the attacker does not need to bypass network or authentication barriers. Exploitation therefore requires legitimate user privileges and knowledge of a page that can be edited visually but not in content. The impact is confined to page metadata rather than core functionality or critical assets.
OpenCVE Enrichment