CVE-2022-47002
Masa CMS - Authentication Bypass
Record summary
CVE-2022-47002 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALMasa CMS - Authentication BypassCVSS 9.8
Masa CMS 7.2, 7.3, and 7.4-beta are susceptible to authentication bypass in the Remember Me function. An attacker can bypass authentication via a crafted web request and thereby obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information and potential compromise of the system.
Remediation
Apply the latest security patch or update provided by the vendor to fix the authentication bypass vulnerability in Masa CMS.
Source: ProjectDiscovery