Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing rights can exploit this to include arbitrary readable files on the server. Combined with the file uploader's extension-only validation (which permits PHP code in files saved with image extensions like .png), this can result in authenticated remote code execution. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 9.4 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H Thanks Yonatan Drori (Tenzai) for reporting.
An authenticated administrator with permissions to edit composer forms can inject path traversal sequences (e.g., '../') into the ptComposerFormLayoutSetControlCustomTemplate field while saving form layouts on the page. This mechanism allows inclusion of any readable file on the server. Since the file uploader validates only the extension (not the actual content), an attacker can previously upload a file containing PHP code saved with a graphics extension (e.g., .png), and then force its inclusion through the vulnerable field – resulting in execution of malicious PHP code.
An attacker can read arbitrary files accessible to the web server process and execute arbitrary code on the server (RCE), which may lead to complete takeover of the system and the environment hosting the application.
Concrete CMS should be updated to version 9.5.1 or newer according to the vendor information available at: https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes
Concrete CMS in version 9.5.0 and lower
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XConcretecms Concrete Cms
APPConcretecms≤ 9.5.0
Related vulnerabilities
Concrete CMS — nieautoryzowany dostęp przez nieprawidłowe uprawnienia katalogów
Concrete CMS — path traversal umożliwiający usunięcie dowolnych plików
Concrete CMS – pobieranie i wykonanie kodu z plików ZIP przez HTTP (RCE)
SSRF w Concrete CMS — ominięcie blokady localhost przez zapis dziesiętny IP
Path Traversal prowadzący do RCE w Concrete CMS przez external form