PT-2026-26082 · Mura Cms · Mura Cms
Published
2026-03-18
·
Updated
2026-03-18
·
CVE-2025-55044
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MuraCMS versions through 10.1.10
Description
A Cross-Site Request Forgery (CSRF) issue exists in the Trash Restore functionality of MuraCMS. The
cTrash.restore function does not validate CSRF tokens. This allows attackers to restore deleted content to unauthorized locations by forging requests when an authenticated administrator visits a malicious webpage. Exploitation involves restoring content to a location specified by the attacker through the parentid parameter. Successful exploitation can lead to the restoration of malicious content, placement of sensitive documents in public areas, or manipulation of the website structure.Recommendations
Versions prior to 10.1.10 are affected.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mura Cms