Concrete CMS vulnerable to Cross-Site Request Forgery (CSRF)
Low severity
GitHub Reviewed
Published
Mar 4, 2026
to the GitHub Advisory Database
•
Updated Mar 4, 2026
Description
Published by the National Vulnerability Database
Mar 4, 2026
Published to the GitHub Advisory Database
Mar 4, 2026
Reviewed
Mar 4, 2026
Last updated
Mar 4, 2026
Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configuration via group_id parameter which can leads to a security bypass since changes are saved prior to checking the CSRF token.
The Concrete CMS security team thanks z3rco for reporting
References