← volver
CVE-2026-6826mediumCWE-200

Concrete 9.5.0 and below has file usage disclosure via missing permission check in Usage controller

28Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendcvss 6.9epss 1.5%
de la publicación al arma0 días
Publicada en NVD21 may
metasploit21 may
probabilidad de explotación
1.5%top 28% de las CVE
explotación observada
noninguna fuente lo reporta
Concrete CMS 9.5.0 and below  is vulnerable to unauthenticated file usage disclosure via missing permission check in the usage controller.  Any unauthenticated visitor can request /ccm/system/dialogs/file/usage/{fID} with any file ID and receive a list of every page that references that file, including page IDs, handles, and full URLs. This includes pages that are otherwise restricted by permissions.The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.9 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Eldudareeno for reporting.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
Concrete CMS · Concrete CMS