PT-2026-26083 · Mura Cms · Mura Cms
CVE-2025-55045
·
Publicado
2026-03-18
·
Atualizado
2026-03-18
CVSS v3.1
7.1
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
MuraCMS versions through 10.1.10
Description
A Cross-Site Request Forgery (CSRF) issue exists in MuraCMS through version 10.1.10, allowing attackers to manipulate user address information. The
cUsers.updateAddress function does not validate CSRF tokens, enabling malicious websites to forge requests. Successful exploitation allows adding, modifying, or deleting user addresses when an authenticated administrator visits a crafted webpage. This can lead to misdirected sensitive communications, compromise of user privacy, disruption of business correspondence, and potential social engineering attacks.Recommendations
Update MuraCMS to a version later than 10.1.10.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mura Cms