Executive brief
Concrete CMS, a popular content management system, contains a security flaw in its conversation messaging system. An unauthorized person can view the full content of any conversation message on the site, including those from private or restricted areas. This could lead to the exposure of sensitive discussions and private file attachments.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in Concrete CMS versions 9.5.0 and below. The '/ccm/frontend/conversations/message_page' endpoint fails to implement proper authorization checks, allowing an unauthenticated attacker to enumerate and retrieve the full content of any conversation message by manipulating identifiers. This exposure includes messages from restricted pages, member-only areas, and the moderation queue, as well as file attachments with their associated download URLs. The vulnerability is addressed in version 9.5.1.
Affected products
- Concrete CMS Concrete CMS <= 9.5.0
Timeline
- 2026-05-21: disclosed: NVD published date
- 2026-05-22: advisory: GitHub Advisory published
- 2026-06-24: patched: Advisory updated with patch information for version 9.5.1