PT-2026-26083 · Mura Cms · Mura Cms
Published
2026-03-18
·
Updated
2026-03-18
·
CVE-2025-55045
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
MuraCMS versions through 10.1.10
Description
A Cross-Site Request Forgery (CSRF) issue exists in MuraCMS through version 10.1.10, allowing attackers to manipulate user address information. The
cUsers.updateAddress function does not validate CSRF tokens, enabling malicious websites to forge requests. Successful exploitation allows adding, modifying, or deleting user addresses when an authenticated administrator visits a crafted webpage. This can lead to misdirected sensitive communications, compromise of user privacy, disruption of business correspondence, and potential social engineering attacks.Recommendations
Update MuraCMS to a version later than 10.1.10.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mura Cms