Impact
Concrete CMS versions 9.2.0 through 9.5.3 contain a deficiency in the REST API user creation endpoint (POST /ccm/api/1.0/users). The controller does not perform a permission check before creating an account. Any OAuth token that carries the users:add scope, including a client_credentials token with no user context, can be used to create active, verified accounts. Those accounts bypass email verification and administrator approval, and under the CMS’s default registration settings can edit page content, providing a path to stored cross‑site scripting and further compromise.
Affected Systems
Concrete CMS installations running versions 9.2.0 up to and including 9.5.3 are affected. Administrators should confirm the exact version deployed and plan an update accordingly.
Risk and Exploitability
The CVSS score of 2.1 denotes a low overall severity, and the EPSS score of less than 1 % suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker must first obtain an OAuth token with the users:add scope, which may be obtained through compromised credentials or a misconfigured OAuth client. Once the token is in hand, the attack can be carried out remotely via the public REST API. Although the immediate impact is limited to the creation of new user accounts, those accounts can subsequently edit content, leading to potential stored XSS and data tampering. The scope of impact therefore extends beyond user creation to content integrity and site trust.
OpenCVE Enrichment