Executive brief
Concrete CMS is a content management system used to build and manage websites. A security flaw in the 'Express' data management component allows a user with limited 'view-only' permissions to change the display order of data entries. This could allow an unauthorized user to manipulate how information is presented to others, potentially disrupting business workflows or data organization.
Technical details
Concrete CMS versions 9.5.0 and below contain an Insecure Direct Object Reference (IDOR) and improper authorization level check within the Express association Reorder dialog. An authenticated attacker with low-level 'view-only' permissions can exploit this flaw to reorder Express entities, a task that should require higher administrative privileges. This results in cross-entity state tampering. The vulnerability specifically affects sites utilizing the Express component and relying on entity ordering. The issue is addressed in version 9.5.1.
Affected products
- Concrete CMS Concrete CMS 5.0 to 9.5.0
Timeline
- 2026-05-22: advisory: NVD and Vendor advisory published
- 2026-05-22: patched: Fixed in version 9.5.1 release notes