Executive brief
Concrete CMS is a popular open-source content management system used to build and manage websites. A vulnerability in its REST API allows users with basic content-editing permissions to modify page properties, templates, and types—and crucially, to inject unescaped JavaScript into page headers that executes for all visitors, including administrators. An attacker could use this to steal credentials from reviewers or take over the site.
Technical details
The REST API endpoint PUT /ccm/api/1.0/pages/{cID} fails to enforce authorization checks on page-property, page-template, and page-type modifications. A user with only content-editing rights can bypass these checks via the REST API and set the header_extra_content attribute, which is rendered unescaped into the HTML head element. This allows persistent cross-site scripting (XSS) that affects all page visitors. The vulnerability requires HTTP network access to the API and a user account with content-editing permissions, but no additional user interaction is needed for the injected script to execute in visitors' browsers. A patch is available in Concrete CMS 9.5.3 and later.
Affected products
- Concrete CMS Concrete CMS 9.2.0 through 9.5.2
Timeline
- 2026-09-14: disclosed