Cross-Site Request Forgery Vulnerability in Concrete CMS by Concrete5
CVE-2026-84432
5.3MEDIUM
What is CVE-2026-84432?
Concrete CMS versions 9 through 9.5.2 are vulnerable due to inadequate validation of anti-CSRF tokens in the Boards custom slot dialog controller. The saveTemplate() action allows attackers to exploit this flaw by dispatching a crafted cross-site request, enabling users with board-edit permissions to unknowingly write attacker-defined slot and template data to their boards. This vulnerability can result in unauthorized modifications without proper session validation, as the action's state-changing database write occurs before any rendering process.
Affected Version(s)
Concrete CMS 9.0.0 <= 9.5.2
