GHSA-fqg3-8w8r-8g94Medium

Concrete CMS has an unauthorized file access issue

Published
May 22, 2026
Last Modified
July 21, 2026

🔗 CVE IDs covered (1)

📋 Description

In Concrete CMS 9.5.0 and below,  the submit_password() method in concrete/controllers/single_page/download_file.php allows unauthorized file access since downloading permission-restricted files bypasses the view_file permission check. Files without passwords can be downloaded and any user who knows a file's password can download a password protected file regardless of whether they have permission to access the file.

🎯 Affected products1

  • composer/concrete5/concrete5:< 9.5.1

🔗 References (3)