PT-2026-57807 · Mura Cms · Mura Cms
CVE-2026-12257
·
Published
2026-07-13
·
Updated
2026-07-15
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Mura CMS versions prior to 10.0.712
Description
A remote code execution issue exists in the '/index.cfm/ api/json/v1/default' endpoint. The
method parameter in POST requests is not properly validated or sanitized before being processed by the ColdFusion engine. This allows a remote attacker to inject and execute arbitrary CFML (ColdFusion Markup Language) expressions and instantiate malicious Java objects.Recommendations
Update to version 10.0.712.
As a temporary workaround, restrict access to the '/index.cfm/ api/json/v1/default' endpoint or avoid using the
method parameter in POST requests to this endpoint.Fix
RCE
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mura Cms