Executive brief
Concrete CMS, a popular content management system, contains a security flaw that allows unauthorized users to view information about private messages. By manipulating message identifiers, an attacker can confirm if a specific message exists and view its rating score. This could lead to the exposure of metadata about private communications within the platform.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in Concrete CMS versions 9.5.0 and below due to missing authorization checks in the '/ccm/frontend/conversations/get_rating' endpoint. An unauthenticated attacker can send network requests to this endpoint with arbitrary message IDs to confirm the existence of messages and retrieve their associated rating scores. This occurs because the application fails to verify if the requester has the appropriate permissions to access the metadata of the specified message object. The issue is addressed in version 9.5.1.
Affected products
- Concrete CMS Concrete CMS <= 9.5.0
Timeline
- 2026-05-21: disclosed: NVD publication date
- 2026-05-22: advisory: GitHub Advisory published
- 2026-06-24: patched: Advisory updated with patch information