在 9.5.3 版本之前,Concrete CMS 的 OAuth 回调登录路径在建立会话时,未检查账户是否处于激活状态或邮箱是否已验证。一个已停用或未经邮箱验证但已绑定 OAuth 的用户,可以完成身份验证并获得一个针对回调响应完全认证的会话,同时登录会被记录,且登录事件也会被触发。 Concrete CMS 安全团队为此漏洞赋予了 CVSS v4.0 评分 6.3,其向量为:CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N。感谢 Te
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 5.0.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81905 | 6.3 MEDIUM | Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a h |
| CVE-2026-18121 | 6.3 MEDIUM | Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) in the Calend |
| CVE-2026-68527 | 5.9 MEDIUM | Concrete CMS 8.3.0 through 9.5.2 is vulnerable to an authorization bypass through user-con |
| CVE-2026-84432 | 5.3 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to CSRFin the Boards custom slot dialog contro |
No comments yet