Impact
Concrete CMS before 9.5.3 contains a flaw in the dashboard’s Theme Inspect controller where the activate_files() action accepts attacker‑supplied pageTemplates[] values without validating an anti‑CSRF token. A malicious web page can automatically post a forged request that, when viewed by an authenticated administrator, creates new PageTemplate records under the administrator’s session, thereby altering site configuration without consent.
Affected Systems
All installations of Concrete CMS running a version older than 9.5.3 are affected. This includes any Concrete CMS setup where the theme page‑template activation feature has not been removed or patched. Upgrading to 9.5.3 or later removes the vulnerability.
Risk and Exploitability
The CVSS v4.0 score of 2.1 indicates low overall severity, yet the attack vector is remote and relies on CSRF, meaning a remote attacker can compromise the site by hosting a malicious page and luring an administrator to load it. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, known exploitation is low, but the potential to alter configuration remains a concern. Administrators should treat this vulnerability as a low‑risk but actionable issue, especially if the site manages sensitive configuration data.
OpenCVE Enrichment