Concrete CMS <9.5.1 - Unauthenticated File-Usage Internal Metadata Disclosure
Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The endpoint /ccm/system/dialogs/file/usage/{fID} accepts an integer file ID in the URL and returns internal site structure data (page IDs, versions, URL paths) to anyone who sends a GET request. References: https://documentation.concretecms.org/9-x/developers/9.5.1-security-releases Remediation: Update to a version later than 9.5.0 or the latest available version.
Used 2.4k times · 1 assets checked · url