PT-2026-26080 · Mura Cms · Mura Cms
Published
2026-03-18
·
Updated
2026-03-18
·
CVE-2025-55041
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MuraCMS versions through 10.1.10
Description
The software contains a Cross-Site Request Forgery (CSRF) issue in the Add To Group functionality within user management, specifically in the
cUsers.cfc addToGroup method. The issue stems from a lack of CSRF token validation, allowing attackers to escalate privileges by adding any user to any group without proper authorization. The vulnerable function directly processes the userId and groupId parameters through getUserManager().createUserInGorup(). Exploitation involves forging requests that automatically execute when an authenticated administrator visits a malicious page. While escalation to the Super Admins group is not possible, attackers can achieve horizontal privilege escalation to other groups and vertical escalation to the admin group.Recommendations
Versions prior to 10.1.10 should be updated.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mura Cms