Back

MEDIUM

Concrete CMS 9.5.0 and below is vulnerable to IDOR in the`/ccm/frontend/conversations/message_detail` endpoint

Published May 21, 2026

Description

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns the full content of any conversation message. An unauthenticated attacker can enumerate all conversation messages, including messages from restricted pages, member-only areas, and the moderation queue. File attachments with download URLs are also exposed. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with Vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Eldudareeno for reporting.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner ConcreteCMS
Published May 21, 2026
Updated May 22, 2026
Reserved May 9, 2026

CISA Vulnrichment

Updated May 22, 2026

NVD

Status Analyzed
Modified Jul 23, 2026

Red Hat

No data

ENISA EUVD

Assigner ConcreteCMS
Published May 21, 2026
Updated May 22, 2026