CyberRota
← Ana sayfaya dön

CVE-2026-8238

MEDIUM · CVSS 5.3 EPSS %0.20

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-05-21T22:16:49.893 · Çekilme zamanı: 2026-06-20T12:03:34.844478+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-8238
Severity
MEDIUM
CVSS
5.3
EPSS
%0.20

Orijinal NVD Açıklaması

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/message_page' endpoint returns the full content of any conversation message. An unauthenticated attacker can enumerate all conversation messages, including messages from restricted pages, member-only areas, and the moderation queue. File attachments with download URLs are also exposed. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with Vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Tristan Madani for reporting.