Executive brief
Concrete CMS, a platform used for building and managing websites, is vulnerable to a security flaw that could allow an attacker to trick a site editor into performing unintended actions. By deceiving a user with file editing permissions, an attacker can force the system to publish an older version of a file or activate an unpublished version created by another user. This could lead to the unauthorized replacement of current website content with outdated or unvetted information.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in Concrete CMS versions 9.5.0 and earlier within the 'Backend\File::approveVersion' method. The application fails to properly validate CSRF tokens when a user with 'edit_file_contents' permissions approves a file version. An attacker can exploit this by inducing a logged-in editor to visit a malicious site, which then triggers a background request to the CMS. This results in the publication of an attacker-selected file version, such as a downgrade to a previous version or the activation of a co-editor's unpublished draft. The vulnerability is addressed in version 9.5.1.
Affected products
- Concrete CMS Concrete CMS <= 9.5.0
Timeline
- 2026-05-22: disclosed: NVD published date
- 2026-05-26: advisory: GitHub Advisory published
- 2026-06-29: patched: GitHub Advisory reviewed and updated with patch information