PT-2026-26083 · Mura Cms · Mura Cms

CVE-2025-55045

·

Publicado

2026-03-18

·

Atualizado

2026-03-18

CVSS v3.1

7.1

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions MuraCMS versions through 10.1.10
Description A Cross-Site Request Forgery (CSRF) issue exists in MuraCMS through version 10.1.10, allowing attackers to manipulate user address information. The cUsers.updateAddress function does not validate CSRF tokens, enabling malicious websites to forge requests. Successful exploitation allows adding, modifying, or deleting user addresses when an authenticated administrator visits a crafted webpage. This can lead to misdirected sensitive communications, compromise of user privacy, disruption of business correspondence, and potential social engineering attacks.
Recommendations Update MuraCMS to a version later than 10.1.10.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-55045

Produtos afetados

Mura Cms