CyberRota Analysis
AI-GeneratedConcrete CMS versions 9.2.0 to 9.5.2 are vulnerable due to a missing authorization check in the REST API Groups list endpoint, allowing authenticated users with the appropriate API token to access all groups on the site without proper permission validation. This could lead to the unauthorized disclosure of sensitive information regarding the organization's group structure and access hierarchy. Organizations using these versions of Concrete CMS should prioritize patching this vulnerability to protect against potential data exposure.
Original NVD Description
Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization vulnerability in the REST API Groups list endpoint. The listGroups() method in concrete/src/Api/Controller/Groups.php registers a permissions checker callback that unconditionally returns true, so no per-object (tree node) authorization is enforced when the group collection is returned. An authenticated user whose API token carries the groups:read scope can call GET /ccm/api/1.0/groups and receive every group on the site regardless of the view permissions on those groups, disclosing the organization's group structure, roles, and access hierarchy. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.0 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.