Concrete CMS 9 至 9.5.2 版本中的主题定制器存在服务器端模板注入(SSTI)漏洞,原因是未对样式值进行验证。通过定制器提交的值(包括颜色通道及其他由 及类似 、 等样式类处理的样式属性)在未经 LESS 语法中性化(即未对特殊字符进行转义或过滤)的情况下,直接插值到服务器端编译的 LESS 源代码中,这使得拥有“主题定制”权限的用户可以注入任意的 LESS 指令。 通过注入 指令,攻击者可以读取服务器上的任意文件,并通过 PHP 流包装器访问内部网络资源。编译后的输出结果(包括任何被披露的文件内
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 9.0.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81908 | 6.0 MEDIUM | Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows |
| CVE-2026-18122 | 6.0 MEDIUM | Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entr |
| CVE-2026-68528 | 6.0 MEDIUM | Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unesca |
| CVE-2026-81909 | 5.9 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block |
No comments yet