CVE-2022-47003

A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.
Configurations

Configuration 1 (hide)

cpe:2.3:a:murasoftware:mura_cms:*:*:*:*:*:*:*:*

History

27 Mar 2025, 15:15

Type Values Removed Values Added
CWE CWE-287

21 Nov 2024, 07:31

Type Values Removed Values Added
References () http://mura.com - Not Applicable () http://mura.com - Not Applicable
References () https://hoyahaxa.blogspot.com/2023/01/preliminary-security-advisory.html - Patch, Third Party Advisory () https://hoyahaxa.blogspot.com/2023/01/preliminary-security-advisory.html - Patch, Third Party Advisory
References () https://hoyahaxa.blogspot.com/2023/03/authentication-bypass-mura-masa.html - () https://hoyahaxa.blogspot.com/2023/03/authentication-bypass-mura-masa.html -
References () https://www.masacms.com/ - Not Applicable () https://www.masacms.com/ - Not Applicable
References () https://www.murasoftware.com/mura-cms/ - Product () https://www.murasoftware.com/mura-cms/ - Product

08 Aug 2023, 14:22

Type Values Removed Values Added
CWE CWE-863 NVD-CWE-Other

06 Mar 2023, 20:15

Type Values Removed Values Added
References
  • (MISC) https://hoyahaxa.blogspot.com/2023/03/authentication-bypass-mura-masa.html -
References (MISC) https://hoyahaxa.blogspot.com/2023/01/preliminary-security-advisory.html - (MISC) https://hoyahaxa.blogspot.com/2023/01/preliminary-security-advisory.html - Patch, Third Party Advisory
References (MISC) http://mura.com - (MISC) http://mura.com - Not Applicable
References (MISC) https://www.masacms.com/ - (MISC) https://www.masacms.com/ - Not Applicable
References (MISC) https://www.murasoftware.com/mura-cms/ - (MISC) https://www.murasoftware.com/mura-cms/ - Product
CPE cpe:2.3:a:murasoftware:mura_cms:*:*:*:*:*:*:*:*
CWE CWE-863
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

01 Feb 2023, 14:45

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-01 14:15

Updated : 2025-03-27 15:15


NVD link : CVE-2022-47003

Mitre link : CVE-2022-47003

CVE.ORG link : CVE-2022-47003


JSON object : View

Products Affected

murasoftware

  • mura_cms
CWE
NVD-CWE-Other CWE-287

Improper Authentication