Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable...
Moderate severity
Unreviewed
Published
Sep 11, 2026
to the GitHub Advisory Database
•
Updated Sep 24, 2026
Description
Published by the National Vulnerability Database
Sep 11, 2026
Published to the GitHub Advisory Database
Sep 11, 2026
Last updated
Sep 24, 2026
Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft a single link on the site's own domain that sends a user to an arbitrary external site immediately after authentication, facilitating phishing and credential theft. The same handling is present in the registration flow, giving a second entry point on sites with registration enabled. Concrete CMS versions prior to 9.5.0 do not include the rcURL parameter or this allowlist and are not affected. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Michal M. for reporting.
References