Executive brief
Concrete CMS, a popular content management system, contains a flaw in its survey component. This vulnerability allows an unauthorized person to cast votes in private or restricted surveys that they should not be able to access. This could lead to manipulated poll results or unauthorized participation in internal company feedback, potentially impacting data integrity and decision-making processes.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in Concrete CMS versions 9.5.0 and below within the survey functionality. The root cause is a lack of proper authorization checks on the survey voting endpoint. If a site hosts both public and private surveys, an unauthenticated attacker can discover the 'optionID' for a restricted survey and submit it through the public survey's endpoint. This allows the attacker to bypass access controls and register votes in surveys intended to be private. The vulnerability is addressed in version 9.5.1.
Affected products
- Concrete CMS Concrete CMS <= 9.5.0
Timeline
- 2026-05-21: disclosed: NVD Published Date
- 2026-05-22: advisory: GitHub Advisory published
- 2026-06-24: patched: Advisory updated with patch information for version 9.5.1