Vulnerabilities > CVE-2017-15639 - XXE vulnerability in Getmura Mura CMS 6.1
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | Mura CMS < 6.2 - Server-Side Request Forgery / XML External Entity Injection. CVE-2017-15639. Webapps exploit for CFM platform |
file | exploits/cfm/webapps/43045.txt |
id | EDB-ID:43045 |
last seen | 2017-10-25 |
modified | 2017-10-24 |
platform | cfm |
port | |
published | 2017-10-24 |
reporter | Exploit-DB |
source | https://www.exploit-db.com/download/43045/ |
title | Mura CMS < 6.2 - Server-Side Request Forgery / XML External Entity Injection |
type | webapps |
Packetstorm
data source | https://packetstormsecurity.com/files/download/144764/muracms-ssrfxxe.txt |
id | PACKETSTORM:144764 |
last seen | 2017-10-27 |
published | 2017-10-26 |
reporter | Anthony Cole |
source | https://packetstormsecurity.com/files/144764/Mura-CMS-Server-Side-Request-Forgery-XXE-Injection.html |
title | Mura CMS Server-Side Request Forgery / XXE Injection |