PT-2026-26084 · Mura Cms · Mura Cms
CVE-2025-55046
·
Publicado
2026-03-18
·
Atualizado
2026-03-18
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MuraCMS versions through 10.1.10
Description
MuraCMS through version 10.1.10 is affected by a Cross-Site Request Forgery (CSRF) issue. An attacker can exploit this to permanently delete all content in the trash system. The
cTrash.empty function does not validate CSRF tokens, allowing a malicious website to forge requests. When an authenticated administrator visits a crafted webpage, the browser automatically submits a form that empties the trash system without confirmation. This can lead to catastrophic data loss within the MuraCMS system.Recommendations
Versions prior to 10.1.10 should be updated.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mura Cms