System running
Last check: 2026-09-29 00:26:08 | Auto-updates every hour
754 PoCs
CybersecPlayground | The ultimate platform for cybersecurity learning & Bug Bounty Resources

CVE-2026-18110-PoC

CVE-2026-18110 General #poc #github #cve-2026-18110 #general
Author
flenz00
Published
2026-09-28
Stars
0
Forks
0
Description

Proof-of-Concept for CVE-2026-18110

CVE-CVE-2026-18110 Details
Severity
HIGH
CVSS Score
7.5
CWE
CWE-862
Description

Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint (/ccm/system/user/autocomplete), which backs the "Preview as User" panel and other user-selector components. The endpoint validates only a CSRF-style access token that is bound to the selector's display options rather than to the caller's identity or permissions, and that token is issued to anonymous visitors because the selector renders without an authorization check. Because ...

Related PoCs for CVE-2026-18110

No other PoCs found for this CVE.

Master Cybersecurity | Join CybersecPlayground for Cybersecurity Learning & Bug Bounty Resources