Concrete CMS 9.5.3 以下版本将用户验证哈希值(用于多种用途,包括邮箱/注册验证、密码重置和持久化登录)统一存储在一个带“类型”列的单表中。然而,哈希值核销(redemption)路径仅根据哈希值本身进行解析,并未校验其对应的用途类型。因此,原本用于某一用途的哈希值可能被用于另一用途:例如,一个长期有效的注册哈希值(有效期 60 天)可被提交到密码修改接口,从而为目标账户设置新密码;而一个密码重置哈希值也可被提交到邮箱验证接口以激活账户。 利用该漏洞的前提是攻击者需通过其他渠道先获取一个有效的哈希值
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 5.0.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81906 | 6.3 MEDIUM | [UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account Checks |
| CVE-2026-18121 | 6.3 MEDIUM | Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) in the Calend |
| CVE-2026-68527 | 5.9 MEDIUM | Concrete CMS 8.3.0 through 9.5.2 is vulnerable to an authorization bypass through user-con |
| CVE-2026-84432 | 5.3 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to CSRFin the Boards custom slot dialog contro |
No comments yet