Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Aaaahuia

#29004of 53,632
8.8Total CVSS
Vulnerabilities · 1
PT-2022-19751
8.8
2022-05-31
Mcms · Mcms · CVE-2022-29647
**Name of the Vulnerable Software and Affected Versions** MCMS version 5.2.7 **Description** An issue was discovered that allows for a CSRF vulnerability, enabling the addition of an administrator account via the "ms/basic/manager/save.do" API endpoint. **Recommendations** For MCMS version 5.2.7, as a temporary workaround, consider restricting access to the "ms/basic/manager/save.do" API endpoint until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.