tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature.
References
Link | Resource |
---|---|
http://www.getmura.com/blog/critical-security-update-for-mura-cms-version-6-1-and-earlier/ | Vendor Advisory |
http://www.securityfocus.com/bid/101603 | Third Party Advisory VDB Entry |
https://www.exploit-db.com/exploits/43045/ | Exploit Third Party Advisory VDB Entry |
http://www.getmura.com/blog/critical-security-update-for-mura-cms-version-6-1-and-earlier/ | Vendor Advisory |
http://www.securityfocus.com/bid/101603 | Third Party Advisory VDB Entry |
https://www.exploit-db.com/exploits/43045/ | Exploit Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 03:14
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.getmura.com/blog/critical-security-update-for-mura-cms-version-6-1-and-earlier/ - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/101603 - Third Party Advisory, VDB Entry | |
References | () https://www.exploit-db.com/exploits/43045/ - Exploit, Third Party Advisory, VDB Entry |
Information
Published : 2017-10-19 19:29
Updated : 2025-04-20 01:37
NVD link : CVE-2017-15639
Mitre link : CVE-2017-15639
CVE.ORG link : CVE-2017-15639
JSON object : View
Products Affected
getmura
- mura_cms
CWE
CWE-611
Improper Restriction of XML External Entity Reference