GHSA-58c8-vvqw-cm7m — concrete5/concrete5
GHSA-58c8-vvqw-cm7m is a CWE-862 vulnerability in concrete5/concrete5. A fix is available for concrete5/concrete5 — see the affected versions and patch details below.
Concrete CMS is vulnerable to IDOR combined with a missing authentication gate
Exploitation Status
No confirmed exploitation observed yet
- CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for GHSA-58c8-vvqw-cm7m.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Real-World Exposure
concrete5/concrete5Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.
Description
Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The endpoint /ccm/system/dialogs/file/usage/{fID} accepts an integer file ID in the URL and returns internal site structure data (page IDs, versions, URL paths) to anyone who sends a GET request. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐘Packagist | concrete5/concrete5 | all versions | 9.5.1composer require concrete5/concrete5:^9.5.1 |
Affected Products
concrete cmsconcretecmsDetection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for concrete5/concrete5, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update concrete5/concrete5 to 9.5.1 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-58c8-vvqw-cm7m is resolved across your whole dependency graph.
Workarounds
Put an independent control in front of the weakness: restrict the affected endpoint or interface to trusted networks, require an additional authentication factor or proxy-level check, and invalidate existing sessions and credentials in case the flaw has already been used.
How to detect GHSA-58c8-vvqw-cm7m
A community-maintained Nuclei template exists for this CVE. You can scan for it directly:
nuclei -id ghsa-58c8-vvqw-cm7m -u https://target- Template
- Concrete CMS <9.5.1 - Unauthenticated File-Usage Internal Metadata Disclosure
- Severity
- medium
- Impact
- Remote attackers can access internal site structure data, potentially exposing sensitive information about the site.
- Remediation
- Update to a version later than 9.5.0 or the latest available version.
Template by ProjectDiscovery nuclei-templates (str4k3r), MIT licensed. View the full template. Scan only systems you are authorised to test.
Frequently Asked Questions
Is GHSA-58c8-vvqw-cm7m in your dependencies?
Find it across Packagist, including transitive dependencies.