MEDIUM
Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in Calendar Block since action_get_events does not check canView on the calendar
Published May 21, 2026
6.3
MEDIUMCVSS 4.0
EPSS 0.35%
Description
Affected products
Remediation
References (4)
Change history (0)
No recorded changes yet.