Executive brief
Concrete CMS is a content management system used to build and manage websites. A security flaw in the bulk page deletion feature allows an attacker to trick an administrator into unintentionally deleting website pages. This occurs if the administrator visits a malicious link while logged into the CMS, potentially leading to unauthorized data loss or site disruption.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in Concrete CMS within the 'concrete/controllers/dialog/page/bulk/delete' component. The application fails to properly validate CSRF tokens or implement sufficient SameSite cookie attributes for requests targeting the bulk delete functionality. An attacker can exploit this by crafting a malicious webpage or link that, when accessed by an authenticated administrator, triggers a background request to delete multiple pages. This vulnerability is mitigated by the requirement for user interaction (the victim must click a link) and specific timing/state requirements. The issue is addressed in version 9.5.1.
Affected products
- Concrete CMS Concrete CMS 9.0.0RC1 through 9.5.0
Timeline
- 2026-05-21: disclosed: NVD publication date
- 2026-05-22: advisory: GitHub Advisory published
- 2026-06-24: patched: Advisory updated with patch information for version 9.5.1