Description
Concrete CMS 9 through 9.5.2 did not validate an anti-CSRF token in the Boards custom slot dialog controller (concrete/controllers/dialog/board/custom_slot.php) saveTemplate() action. The action created a board_slot_proxy Block and dispatched an AddCustomSlotToBoardCommand against a board instance while gating only on the per-resource canEditBoardContents() permission, so a crafted cross-site request could cause a user holding board-edit permission with an active session to write attacker-chosen slot and template data to a board under their own authority. The state-changing database write completed before any downstream rendering, so the forged request succeeded even when the HTTP response returned a non-200 status. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
Published: 2026-09-10
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized board slot data creation via CSRF
Action: Patch
AI Analysis

Impact

The vulnerability lies in Concrete CMS 9 through 9.5.2 where the Boards custom slot dialog controller fails to validate an anti‑CSRF token. An attacker can craft a cross‑site request that, when executed by a user who holds board‑edit permissions and has an active session, creates a board_slot_proxy Block and dispatches an AddCustomSlotToBoardCommand. The database write occurs before any downstream rendering, so the crafted request succeeds even if the HTTP response is non‑200. The result is unauthorized alteration of board content, which constitutes a moderate integrity violation under CWE‑352.

Affected Systems

Concrete CMS versions 9 up to and including 9.5.2 are affected. The flaw resides in the concrete/controllers/dialog/board/custom_slot.php saveTemplate() action, which is part of the default board functionality provided by the publisher. All installations using these versions are therefore potentially vulnerable if they have boards editable by users.

Risk and Exploitability

The CVSS score of 5.3 categorises this flaw as a moderate impact issue. Attackers in can coerce a legitimate user who already has edit rights on a board to submit a forged request. Because the vulnerability only requires the per‑resource canEditBoardContents() permission and does not involve additional authentication, the likelihood of successful exploitation is contingent on the prevalence of such users and may be higher in sites with many boards. EPSS data is currently unavailable, so the exploitation probability cannot be explicitly quantified, but the lack of a KEV listing suggests no widespread exploitation has been observed. Nonetheless, once triggered, the attack writes arbitrary slot and template data to the board database, causing integrity violations and potentially allowing further configuration changes under the victim’s authority.

Generated by OpenCVE AI on September 10, 2026 at 22:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to the latest release that adds CSRF validation to the Boards custom slot dialog controller.
  • Limit board‑edit permissions to the smallest set of trusted users and enforce the principle of least privilege.
  • Deploy a web application firewall rule to detect and block forged POST requests to the boards custom slot endpoint.

Generated by OpenCVE AI on September 10, 2026 at 22:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description Concrete CMS 9 through 9.5.2 did not validate an anti-CSRF token in the Boards custom slot dialog controller (concrete/controllers/dialog/board/custom_slot.php) saveTemplate() action. The action created a board_slot_proxy Block and dispatched an AddCustomSlotToBoardCommand against a board instance while gating only on the per-resource canEditBoardContents() permission, so a crafted cross-site request could cause a user holding board-edit permission with an active session to write attacker-chosen slot and template data to a board under their own authority. The state-changing database write completed before any downstream rendering, so the forged request succeeded even when the HTTP response returned a non-200 status. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
Title Concrete CMS 9 through 9.5.2 is vulnerable to CSRFin the Boards custom slot dialog controller
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-10T19:27:52.523Z

Reserved: 2026-09-01T18:52:23.770Z

Link: CVE-2026-84432

cve-icon Vulnrichment

Updated: 2026-09-10T19:27:49.737Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T20:17:28.803

Modified: 2026-09-10T20:44:57.447

Link: CVE-2026-84432

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:45:17Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)