{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/concretecms/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":5.3,"id":"CVE-2026-8239"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Concrete Cms (\u003c 9.5.1)"],"_cs_severities":["medium"],"_cs_tags":["idor","information-disclosure","web-application","reconnaissance"],"_cs_type":"advisory","_cs_vendors":["Concretecms"],"content_html":"\u003cp\u003eConcrete CMS versions 9.5.0 and earlier are affected by an Insecure Direct Object Reference (IDOR) vulnerability, tracked as CVE-2026-8239. The vulnerability exists within the '/ccm/frontend/conversations/get_rating' endpoint. This endpoint accepts a 'message_id' parameter via a GET request and returns the rating score of the corresponding message. Crucially, the application fails to perform any authorization checks to verify if the requester has permission to access the requested message object.\u003c/p\u003e\n\u003cp\u003eBy supplying sequential or arbitrary numeric identifiers in the 'message_id' parameter, an unauthenticated attacker can determine the existence of private messages and retrieve their associated rating scores. This information disclosure flaw allows for the enumeration of messages within the system. The issue is remediated in Concrete CMS version 9.5.1, which introduces authorization checks to ensure users can only access information for which they have explicit permissions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to conduct reconnaissance on system messaging activity. By iterating through message IDs, an attacker can confirm the existence of private conversations and extract rating data, leading to the exposure of information that should otherwise be restricted. While the impact is limited to metadata (ratings) and existence confirmation, it poses a privacy risk in environments where message interactions are intended to be confidential.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the upgrade of all instances of Concrete CMS to version 9.5.1 or later to remediate CVE-2026-8239. For defenders, monitor web server logs for high-frequency or anomalous access to the '/ccm/frontend/conversations/get_rating' endpoint, particularly those involving sequential or rapid incrementation of the 'messageId' or 'message_id' query parameters.\u003c/p\u003e\n","date_modified":"2026-08-31T01:18:37Z","date_published":"2026-08-31T01:18:37Z","id":"https://feed.craftedsignal.io/briefs/2026-08-concrete-cms-idor/","summary":"Concrete CMS versions prior to 9.5.1 contain an IDOR vulnerability in the get_rating endpoint that allows unauthenticated attackers to enumerate message IDs and disclose rating data for private content.","title":"Concrete CMS IDOR Vulnerability in Conversation Rating Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-08-concrete-cms-idor/"}],"language":"en","title":"CraftedSignal Threat Feed - Concretecms","version":"https://jsonfeed.org/version/1.1"}