GHSA-jqvq-gv67-3567Low

Concrete CMS is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog

Published
May 26, 2026
Last Modified
June 29, 2026

🔗 CVE IDs covered (1)

📋 Description

Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog.  This can cause Cross-entity state tampering with view-only permission on one entry. To be affected, a website has to be using express and relying on express entity ordering. Thanks Winston Crooker for reporting.

🎯 Affected products1

  • composer/concrete5/concrete5:< 9.5.1

🔗 References (3)