CyberRota Analysis
AI-GeneratedConcrete CMS versions prior to 9.5.3 are vulnerable due to a lack of anti-CSRF token validation on the block-arrangement backend endpoint, allowing attackers to exploit this weakness. By tricking a signed-in content editor into loading a malicious page, an attacker could reorder or move blocks in the draft version of a page without proper authorization. Organizations using Concrete CMS, especially those with content editors, should prioritize addressing this vulnerability to mitigate potential unauthorized changes to their web content.
Original NVD Description
Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrangement backend endpoint (the arrange() action of Concrete\Controller\Backend\Page\ArrangeBlocks). The action enforced page-edit authorization but performed no token check, and its route accepted any HTTP method, so an attacker could induce a signed-in content editor into loading an attacker-controlled page that auto-submitted a cross-site request and reordered or moved blocks in the draft version of a page the victim was permitted to edit. The default null cookie SameSite configuration let the victim's session cookie accompany the forged request. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.