PT-2026-26082 · Mura Cms · Mura Cms

CVE-2025-55044

·

Publicado

2026-03-18

·

Atualizado

2026-03-18

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MuraCMS versions through 10.1.10
Description A Cross-Site Request Forgery (CSRF) issue exists in the Trash Restore functionality of MuraCMS. The cTrash.restore function does not validate CSRF tokens. This allows attackers to restore deleted content to unauthorized locations by forging requests when an authenticated administrator visits a malicious webpage. Exploitation involves restoring content to a location specified by the attacker through the parentid parameter. Successful exploitation can lead to the restoration of malicious content, placement of sensitive documents in public areas, or manipulation of the website structure.
Recommendations Versions prior to 10.1.10 are affected.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-55044

Produtos afetados

Mura Cms