CyberRota Analysis
AI-GeneratedConcrete CMS versions prior to 9.5.3 are susceptible to Cross-Site Request Forgery (CSRF) on the dashboard's SEO Excluded Words page, allowing attackers to manipulate the reserved-word list without proper validation. This vulnerability can lead to unauthorized changes in URL-slug generation, potentially undermining the site's SEO configuration. Administrators and security teams managing Concrete CMS installations should prioritize patching to mitigate this risk.
Original NVD Description
Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page. The reset() controller action cleared the administrator-configured reserved-word list (concrete.seo.exclude_words) but did not validate the anti-CSRF token that the reset modal emitted, and it did not restrict the request to the POST method. A remote attacker who lured an authenticated user with SEO access to a crafted page could revert the reserved-word list to its default and silently alter future URL-slug generation for pages, files, topics, and other objects created through the Text urlify service, undoing the site's configured SEO slug policy. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.