Executive brief
Concrete CMS is a content management system used to build and manage websites. Versions 9.5.0 through 9.5.2 contain an open redirect vulnerability in the authentication and registration flows that allows an attacker to craft a link on the legitimate site's domain that silently redirects authenticated users to an attacker-controlled website, enabling phishing attacks and credential theft.
Technical details
The vulnerability is an open redirect flaw in the rcURL parameter handling within Concrete CMS authentication and registration flows. An attacker can craft a specially crafted URL on the affected site's domain that passes an arbitrary external URL via the rcURL parameter, which lacks proper allowlist validation. When a user clicks the attacker's link and authenticates, they are immediately redirected to the attacker-controlled site without warning. No authentication is required to craft the malicious URL, and user interaction (clicking the link) is the only precondition. Concrete CMS versions prior to 9.5.0 are unaffected as they do not include the rcURL parameter feature. A patch is expected in a version following 9.5.2.
Affected products
- Concrete CMS Concrete CMS 9.5.0 through 9.5.2
Timeline
- 2026-09-11: disclosed