Impact
The vulnerability lies in Concrete CMS 9 through 9.5.2 where the Boards custom slot dialog controller fails to validate an anti‑CSRF token. An attacker can craft a cross‑site request that, when executed by a user who holds board‑edit permissions and has an active session, creates a board_slot_proxy Block and dispatches an AddCustomSlotToBoardCommand. The database write occurs before any downstream rendering, so the crafted request succeeds even if the HTTP response is non‑200. The result is unauthorized alteration of board content, which constitutes a moderate integrity violation under CWE‑352.
Affected Systems
Concrete CMS versions 9 up to and including 9.5.2 are affected. The flaw resides in the concrete/controllers/dialog/board/custom_slot.php saveTemplate() action, which is part of the default board functionality provided by the publisher. All installations using these versions are therefore potentially vulnerable if they have boards editable by users.
Risk and Exploitability
The CVSS score of 5.3 categorises this flaw as a moderate impact issue. Attackers in can coerce a legitimate user who already has edit rights on a board to submit a forged request. Because the vulnerability only requires the per‑resource canEditBoardContents() permission and does not involve additional authentication, the likelihood of successful exploitation is contingent on the prevalence of such users and may be higher in sites with many boards. EPSS data is currently unavailable, so the exploitation probability cannot be explicitly quantified, but the lack of a KEV listing suggests no widespread exploitation has been observed. Nonetheless, once triggered, the attack writes arbitrary slot and template data to the board database, causing integrity violations and potentially allowing further configuration changes under the victim’s authority.
OpenCVE Enrichment