LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2025-55040

murasoftware · mura cms

Published
CVSS8.8
Severityhigh
WeaknessCWE-352
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack. The vulnerable cForm.importform function lacks CSRF token validation, enabling malicious websites to forge file upload requests that install attacker-controlled forms when an authenticated administrator visits a crafted webpage. Full exploitation of this vulnerability would require the victim to select a malicious ZIP file containing form definitions, which can be automatically generated by the exploit page and used to create data collection forms that steal sensitive information. Successful exploitation of the import form CSRF vulnerability c

References

← Back to the CVE Tracker

Our coverage of CVE-2025-55040

No stories yet. This page updates automatically when we publish reporting that references CVE-2025-55040.