Record summary

CVE-2022-47002 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryCRITICALMasa CMS - Authentication BypassCVSS 9.8

Masa CMS 7.2, 7.3, and 7.4-beta are susceptible to authentication bypass in the Remember Me function. An attacker can bypass authentication via a crafted web request and thereby obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information and potential compromise of the system.

Remediation

Apply the latest security patch or update provided by the vendor to fix the authentication bypass vulnerability in Masa CMS.

WeaknessesCWE-863
Authorsiamnoooob, rootxharsh, pdresearch
Template tagscvecve2022auth-bypasscmsmasamasacmsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*
Shodan: Generator: Masa CMS
Shodan: generator: masa cms

Source: ProjectDiscovery

References

6