Executive brief
Concrete CMS is a content management system used to build and manage websites. An attacker can trick an authenticated administrator into moving user groups to different parent groups without their knowledge or consent. Because group membership determines what permissions users inherit, a malicious move operation can alter user permissions and access controls across the entire system.
Technical details
The vulnerability is a Cross-Site Request Forgery (CSRF) in the dashboard/users/groups/bulkupdate/confirm() endpoint. The endpoint processes requests to move selected group tree nodes but fails to validate an action token, allowing an unauthenticated attacker to craft a forged request that will be executed if a logged-in administrator visits a malicious page. The attack requires the victim to be authenticated as an administrator and to interact with the attacker's page (UI interaction required). Successful exploitation allows an attacker to relocate group hierarchies, causing group members to inherit unintended parent group permissions, thereby escalating or modifying authorization levels. The vulnerability has been assigned CVSS v4.0 score 5.7 (medium severity) and patches are available in version 9.5.3 and later.
Affected products
- Concrete CMS Concrete CMS before 9.5.3
Timeline
- 2026-09-11: disclosed