A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://mura.com | not applicable |
https://www.masacms.com/ | not applicable |
https://www.murasoftware.com/mura-cms/ | product |
https://hoyahaxa.blogspot.com/2023/01/preliminary-security-advisory.html | third party advisory patch |
https://hoyahaxa.blogspot.com/2023/03/authentication-bypass-mura-masa.html |