tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature.
References
Link | Resource |
---|---|
http://www.getmura.com/blog/critical-security-update-for-mura-cms-version-6-1-and-earlier/ | Vendor Advisory |
https://www.exploit-db.com/exploits/43045/ | Exploit Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/101603 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2017-10-19 12:29
Updated : 2017-11-08 05:50
NVD link : CVE-2017-15639
Mitre link : CVE-2017-15639
JSON object : View
CWE
CWE-611
Improper Restriction of XML External Entity Reference
Products Affected
getmura
- mura_cms