PT-2026-38226 · Masacms · Masacms

·

CVE-2026-40174

·

Published

2026-05-06

·

Updated

2026-05-07

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Masa CMS versions prior to 7.2.10 Masa CMS versions prior to 7.3.15 Masa CMS versions prior to 7.4.10 Masa CMS versions prior to 7.5.3
Description The cUsers.updateAddress() function fails to properly validate anti-CSRF (Cross-Site Request Forgery) tokens during user address management operations. This allows an attacker to trick an authenticated administrator into submitting a forged request to add, modify, or delete user address records, such as email addresses and phone numbers. This could lead to the corruption of user directory data and the redirection of organizational communications.
Recommendations Update to version 7.2.10. Update to version 7.3.15. Update to version 7.4.10. Update to version 7.5.3. Restrict access to the administrative backend. Use browser isolation for administrative sessions. Deploy filtering rules to block forged requests to the affected endpoint.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40174
GHSA-572M-P246-4356

Affected Products

Masacms