Executive brief
Concrete CMS, a popular content management system, is vulnerable to a security flaw that could allow an attacker to trick an administrator into unintentionally deleting system logs. By persuading a logged-in user to click a malicious link or visit a compromised website, the attacker can trigger the bulk deletion of logs without the user's consent. This can hinder security auditing and incident response by removing records of system activity.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in Concrete CMS within the 'concrete/controllers/dialog/logs/bulk/delete' controller. The application fails to properly validate CSRF tokens or implement sufficient SameSite cookie attributes for requests sent to this endpoint. An unauthenticated remote attacker can exploit this by inducing a logged-in administrator to submit a specially crafted web request, leading to the unauthorized bulk deletion of system logs. This issue is addressed in version 9.5.1.
Affected products
- Concrete CMS Concrete CMS 9.0.0RC1 to 9.5.0
Timeline
- 2026-05-21: disclosed: NVD publication date
- 2026-05-22: advisory: GitHub Advisory published
- 2026-06-24: patched: Advisory updated with patch information for version 9.5.1