Executive brief
Concrete CMS, a popular open-source content management system, contains a flaw in its calendar feature that allows unauthorized access to event details. An attacker can view event metadata (title, date, description, page links, and custom attributes) from calendars they should not have access to by manipulating event identifiers in the calendar lightbox viewer. This could expose sensitive event information and compromise the confidentiality of calendar content across multiple websites using this CMS.
Technical details
The vulnerability is an insecure direct object reference (IDOR) in the frontend calendar lightbox endpoint at /ccm/calendar/view_event/{bID}/{occurrence_id}. The controller loads calendar event occurrences based on attacker-supplied sequential identifiers without verifying that the occurrence belongs to the calendar block specified in the request, and without authenticating the caller's permission to view the calendar. An unauthenticated attacker who can access any public calendar block with lightbox functionality enabled can enumerate arbitrary occurrence identifiers to disclose event metadata from restricted calendars. No authentication is required, and the attack requires only network access and parameter manipulation. A patch is expected from the Concrete CMS security team.
Affected products
- Concrete CMS Concrete CMS 9.5.2 and below
Timeline
- 2026-09-11: disclosed