Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-7886

Опубликовано: 21 мая 2026
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter which can lead to file permission bypass. The AddMessage and UpdateMessage conversation controllers accept user-supplied file attachment IDs and load files directly via $em->find(File::class, $attachmentID) without checking per-file permissions (canViewFile()). A user who can post in any conversation can reference any file in the CMS file manager by its sequential ID, effectively bypassing the file permission system.  The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with a vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Tristan Mandani for reporting. if a site truly has private files, the owner should set up a private storage location https://documentation.concretecms.org/user-guide/editors-reference/dashboard/system-and-maintenance/files/file-storage-locations outside of the webroot so that permission

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Версия до 9.5.1 (исключая)

EPSS

Процентиль: 21%
0.00288
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

github
2 месяца назад

Concrete CMS is vulnerable to IDOR in AddMessage/UpdateMessage

EPSS

Процентиль: 21%
0.00288
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-639