Executive brief
Squidex CMS, a platform used for managing and delivering digital content, is vulnerable to a security flaw in its user profile management component. An attacker can trick an authenticated administrator or user into visiting a malicious webpage that secretly interacts with the CMS in the background. This could allow the attacker to change account details, such as email addresses, potentially leading to full account takeover and unauthorized access to sensitive content.
Technical details
A Cross-Site Request Forgery (CSRF) and Clickjacking vulnerability exists in Squidex CMS versions 0 through 7.21.0 within the IdentityServer account profile endpoint. The application fails to implement sufficient frame protection (such as CSP frame-ancestors or X-Frame-Options) and lacks adequate request verification on sensitive profile actions. An attacker can host a malicious HTML page (potentially as an uploaded asset within the CMS itself) that frames the profile management page. By using UI redress (clickjacking), the attacker can induce an authenticated victim to perform unintended actions, such as changing their account email address. Since the application may not require verification for email changes, this allows the attacker to pivot into account recovery and escalate privileges.
Affected products
- Squidex.io Squidex CMS 0 through 7.21.0
Timeline
- 2026-06-29: disclosed: Vulnerability published to NVD