Back

MEDIUM

Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/get_rating'

Published May 21, 2026

Description

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/get_rating' endpoint confirms existence and returns rating score for any message by ID. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with Vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Tristan Madani for reporting.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ConcreteCMS
Published May 21, 2026
Updated May 22, 2026
Reserved May 9, 2026
CISA Vulnrichment
Updated May 22, 2026
NVD
Status Analyzed
Modified Jul 23, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-2XP7-RPVC-PJWC