Record summary

CVE-2022-47003 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 27, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryCRITICALMura CMS <10.0.580 - Authentication BypassCVSS 9.8

Mura CMS before 10.0.580 is susceptible to authentication bypass in the Remember Me function. An attacker can bypass authentication via a crafted web request and thereby obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability allows an attacker to bypass authentication and gain unauthorized access to the Mura CMS application.

Remediation

Upgrade Mura CMS to version 10.0.580 or later to mitigate this vulnerability.

WeaknessesCWE-863
Authorsiamnoooob, rootxharsh, pdresearch
Template tagscvecve2022auth-bypasscmsmuramurasoftwarevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:murasoftware:mura_cms:*:*:*:*:*:*:*:*
Shodan: Generator: Mura CMS
Shodan: generator: mura cms

Source: ProjectDiscovery

References

6