PT-2023-15129 · Masacms · Masacms

Brian

·

Published

2023-02-01

·

Updated

2023-12-21

·

CVE-2022-47002

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Masa CMS versions 7.2 through 7.4-beta
Description A vulnerability in the Remember Me function of Masa CMS allows attackers to bypass authentication via a crafted web request.
Recommendations For versions 7.2 through 7.4-beta, consider disabling the Remember Me function as a temporary workaround until a patch is available.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-47002

Affected Products

Masacms