LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2025-55045

murasoftware · mura cms

Published
CVSS7.1
Severityhigh
WeaknessCWE-352
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N

Description

The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information through CSRF. The vulnerable cUsers.updateAddress function lacks CSRF token validation, enabling malicious websites to forge requests that add, modify, or delete user addresses when an authenticated administrator visits a crafted webpage. Successful exploitation of the update address CSRF vulnerability results in unauthorized manipulation of user address information within the MuraCMS system, potentially compromising user data integrity and organizational communications. When an authenticated administrator visits a malicious webpage containing the CSRF exploit, their brows

References

← Back to the CVE Tracker

Our coverage of CVE-2025-55045

No stories yet. This page updates automatically when we publish reporting that references CVE-2025-55045.