在 Concrete CMS 9.2.0 至 9.5.3 版本中,REST API 的用户创建端点(POST /ccm/api/1.0/users,对应 concrete/src/Api/Controller/Users.php 文件中的 add() 方法)在创建账户前未执行权限检查。因此,任何携带 users:add 权限范围的合法 OAuth 令牌(包括没有关联用户上下文的 client_credentials 令牌)都可以创建处于活跃状态且已验证的用户账户,从而绕过邮箱验证和管理员审批流程。在默认注册设置下,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 9.2.0 ~ 9.5.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85385 | 7.7 HIGH | Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field |
| CVE-2026-85386 | 7.3 HIGH | Concrete CMS before 9.5.4 stored is vulneratble to cross-site scripting via unauthenticate |
| CVE-2026-18120 | 6.3 MEDIUM | Missing Authorization in legacy Express entries search endpoint allows disclosure of Expre |
| CVE-2026-87028 | 5.3 MEDIUM | Cross-Board IDOR in the Board Custom Slot Preview in Concrete CMS 9.0.0 through 9.5.3 Disc |
| CVE-2026-85387 | 2.0 LOW | Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST API |
No comments yet