Vendor
Concrete CMS versions prior to 9.5.1 contain an IDOR vulnerability in the get_rating endpoint that allows unauthenticated attackers to enumerate message IDs and disclose rating data for private content.