PT-2026-26084 · Mura Cms · Mura Cms
Published
2026-03-18
·
Updated
2026-03-18
·
CVE-2025-55046
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MuraCMS versions through 10.1.10
Description
MuraCMS through version 10.1.10 is affected by a Cross-Site Request Forgery (CSRF) issue. An attacker can exploit this to permanently delete all content in the trash system. The
cTrash.empty function does not validate CSRF tokens, allowing a malicious website to forge requests. When an authenticated administrator visits a crafted webpage, the browser automatically submits a form that empties the trash system without confirmation. This can lead to catastrophic data loss within the MuraCMS system.Recommendations
Versions prior to 10.1.10 should be updated.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mura Cms