GHSA-xjg6-5v39-v7fcLow

Concrete CMS is vulnerable to CSRF via Backend\File::approveVersion

Published
May 26, 2026
Last Modified
June 29, 2026

🔗 CVE IDs covered (1)

📋 Description

Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents permission is CSRF'd into publishing an attacker-chosen previously-uploaded version (downgrade to an older version of a file, or activation of a co-editor's unpublished version). Thanks Winston Crooker for reporting.

🎯 Affected products1

  • composer/concrete5/concrete5:< 9.5.1

🔗 References (3)