PT-2026-26082 · Mura Cms · Mura Cms

Published

2026-03-18

·

Updated

2026-03-18

·

CVE-2025-55044

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MuraCMS versions through 10.1.10
Description A Cross-Site Request Forgery (CSRF) issue exists in the Trash Restore functionality of MuraCMS. The cTrash.restore function does not validate CSRF tokens. This allows attackers to restore deleted content to unauthorized locations by forging requests when an authenticated administrator visits a malicious webpage. Exploitation involves restoring content to a location specified by the attacker through the parentid parameter. Successful exploitation can lead to the restoration of malicious content, placement of sensitive documents in public areas, or manipulation of the website structure.
Recommendations Versions prior to 10.1.10 are affected.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-55044

Affected Products

Mura Cms