PT-2026-42555 · Unknown · Concrete Cms
Tristan Mandani
·
Published
2026-05-21
·
Updated
2026-05-22
·
CVE-2026-7882
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions prior to 9.5.1
Description
An inverted CSRF token check in the
DeleteFile controller allows unauthorized file deletion. The system incorrectly throws an error when the token is valid and proceeds with the deletion process when the token is invalid or missing. This flaw disables Cross-Site Request Forgery (CSRF) protection—a mechanism used to prevent unauthorized commands from being transmitted from a user the web application trusts—for the file deletion endpoint, enabling attacks against users with permissions to edit conversation messages.Recommendations
Update to a version newer than 9.5.0.
As a temporary workaround, restrict access to the
DeleteFile controller to minimize the risk of unauthorized file deletion.Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms