PT-2026-26082 · Mura Cms · Mura Cms
CVE-2025-55044
·
Publicado
2026-03-18
·
Atualizado
2026-03-18
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MuraCMS versions through 10.1.10
Description
A Cross-Site Request Forgery (CSRF) issue exists in the Trash Restore functionality of MuraCMS. The
cTrash.restore function does not validate CSRF tokens. This allows attackers to restore deleted content to unauthorized locations by forging requests when an authenticated administrator visits a malicious webpage. Exploitation involves restoring content to a location specified by the attacker through the parentid parameter. Successful exploitation can lead to the restoration of malicious content, placement of sensitive documents in public areas, or manipulation of the website structure.Recommendations
Versions prior to 10.1.10 are affected.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mura Cms