Impact
Concrete CMS versions 9.0.0 through 9.5.3 did not validate that a board item submitted to the custom-slot preview endpoint belonged to the board the requesting user was authorized to edit, and it also did not enforce that the requester had permission to view the page that backs the summary content. This flaw is an Authorization bypass (CWE‑862) that lets an authenticated user holding the edit-board-contents privilege submit an identifier belonging to a different board instance and receive summary fields—including the page title and description—of an underlying page the user was otherwise denied to view.
Affected Systems
All concrete CMS deployments using edition 9.0.0 through 9.5.3, specifically those utilizing board modules with custom‑slot previews, are impacted. The issue surfaces when an authenticated user with editing rights submits a board item identifier that references a board outside the user’s authorized scope.
Risk and Exploitability
The vulnerability carries a CVSS v4.0 score of 5.3, indicating moderate impact. Its EPSS score is less than 1 %, denoting a very low current exploitation probability, and it is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with edit-board-contents permission and knowledge of a valid item ID from another board instance. The attack does not require remote access or additional privileges beyond those already held by legitimate editors. Consequently, the overall risk level is moderate, and the likelihood of active exploitation is low at present.
OpenCVE Enrichment