Concrete CMS is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog
Low severity
GitHub Reviewed
Published
May 26, 2026
to the GitHub Advisory Database
•
Updated Jun 29, 2026
Description
Published by the National Vulnerability Database
May 22, 2026
Published to the GitHub Advisory Database
May 26, 2026
Reviewed
Jun 29, 2026
Last updated
Jun 29, 2026
Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog. This can cause Cross-entity state tampering with view-only permission on one entry. To be affected, a website has to be using express and relying on express entity ordering. Thanks Winston Crooker for reporting.
References