Executive brief
Concrete CMS, a platform used for building and managing websites, contains a security flaw that allows unauthorized access to private conversation data. An attacker can view the full content of any message on the site, including those from restricted member areas or moderation queues, without needing to log in. This could lead to the exposure of sensitive communications and private file attachments.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in Concrete CMS versions 9.5.0 and below due to missing authorization checks in the `/ccm/frontend/conversations/message_detail` endpoint. An unauthenticated attacker can exploit this by enumerating message identifiers to retrieve the full content of any conversation message. This includes messages from restricted pages, member-only areas, and the moderation queue, as well as file attachments with their associated download URLs. The vulnerability is addressed in version 9.5.1.
Affected products
- Concrete CMS Concrete CMS <= 9.5.0
Timeline
- 2026-05-21: disclosed: NVD Published Date
- 2026-05-22: advisory: GitHub Advisory published
- 2026-06-24: patched: GitHub Advisory reviewed and updated with patch info