PT-2026-30938 · Mrcms+1 · Mrcms+1
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MRCMS version 3.1.2
Description
An access control issue exists where the
save() function in the UserController.java file lacks proper authorization validation. This allows the direct addition of super administrator accounts without requiring authentication.Recommendations
Update MRCMS version 3.1.2 to a patched version.
As a temporary mitigation, restrict access to the
save() function within the UserController.java controller.Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mrcms
Mushroom