Executive brief
Concrete CMS, a popular content management system, is vulnerable to a security flaw that could allow an attacker to take over a website. By tricking a logged-in administrator into visiting a malicious link, an attacker can force the system to install a malicious software package. If successful, this allows the attacker to execute arbitrary code on the server, potentially leading to full site compromise and data theft.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the install_package() method within concrete/controllers/single_page/dashboard/extend/install.php. The vulnerability allows an attacker to bypass CSRF protections and force the installation of a package if they can place a malicious package directory under DIR_PACKAGES/<handle>/ and trick an authenticated administrator with 'canInstallPackages' permissions into visiting a crafted URL. Upon installation, the package controller's install() method is executed as the web server user, resulting in remote code execution (RCE). This issue is addressed in version 9.5.1.
Affected products
- Concrete CMS Concrete CMS <= 9.5.0
Timeline
- 2026-05-21: disclosed
- 2026-05-21: advisory
- 2026-05-21: patched: Fixed in version 9.5.1